Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-2229 |
|
Vulnerability in c (CVE-2026-2229)
vulnerability in c (CVE-2026-2229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1528 |
|
Vulnerability in nodejs (CVE-2026-1528)
vulnerability in nodejs (CVE-2026-1528). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1526 |
|
Vulnerability in nodejs (CVE-2026-1526)
vulnerability in nodejs (CVE-2026-1526). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-55130 |
|
Vulnerability in node-min (CVE-2025-55130)
vulnerability in node-min (CVE-2025-55130). Confidential information can be exposed externally. Mitigation: upgrade to `20.20.0, 22.22.0, 24.13.0, 25.3.0` or later.
|
| CVE-2025-59465 |
|
Vulnerability in node (CVE-2025-59465)
vulnerability in node (CVE-2025-59465). Risk of unauthorized operations or information disclosure. Exploitable via ``HPACK``. Mitigation: upgrade to `20.20.0, 22.22.0, 24.13.0, 25.3.0` or later.
|
| CVE-2024-3566 |
|
Command Injection in node (CVE-2024-3566)
command injection in node (CVE-2024-3566). Successful exploitation can lead to full system takeover. Exploitable via ``cmd.exe``. Mitigation: upgrade to `18.19.0` or later.
|
| CVE-2023-44487 KEV |
|
[KEV] Vulnerability in Ietf golang.org/x/net (CVE-2023-44487)
vulnerability in Ietf golang.org/x/net (CVE-2023-44487). Risk of unauthorized operations or information disclosure. Exploitable via ``Channel``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.17.0` or later.
|
| CVE-2022-0778 |
|
Vulnerability in dos (CVE-2022-0778)
vulnerability in dos (CVE-2022-0778). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-1971 |
|
Vulnerability in dos (CVE-2020-1971)
vulnerability in dos (CVE-2020-1971). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-15897 |
|
Vulnerability in nodejs (CVE-2017-15897)
vulnerability in nodejs (CVE-2017-15897). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-15896 |
|
Vulnerability in nodejs (CVE-2017-15896)
vulnerability in nodejs (CVE-2017-15896). Confidential information can be exposed externally.
|
| CVE-2017-3738 |
|
Information Disclosure in openssl (CVE-2017-3738)
vulnerability in openssl (CVE-2017-3738). Confidential information can be exposed externally.
|
| CVE-2017-14919 |
|
Vulnerability in dos (CVE-2017-14919)
vulnerability in dos (CVE-2017-14919). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-3744 |
|
Path Traversal in path-traversal (CVE-2014-3744)
path traversal in path-traversal (CVE-2014-3744). Confidential information can be exposed externally.
|
| CVE-2015-7384 |
|
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
|
| CVE-2017-14849 |
|
Path Traversal in nodejs (CVE-2017-14849)
path traversal in nodejs (CVE-2017-14849). Confidential information can be exposed externally.
|
| CVE-2015-2927 |
|
Vulnerability in dos (CVE-2015-2927)
vulnerability in dos (CVE-2015-2927). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11499 |
|
Vulnerability in dos (CVE-2017-11499)
vulnerability in dos (CVE-2017-11499). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-1000381 |
|
Information Disclosure in c (CVE-2017-1000381)
vulnerability in c (CVE-2017-1000381). Confidential information can be exposed externally.
|
| CVE-2016-9841 |
|
Vulnerability in c (CVE-2016-9841)
vulnerability in c (CVE-2016-9841). Successful exploitation can lead to full system takeover.
|
| CVE-2016-9843 |
|
Vulnerability in c (CVE-2016-9843)
vulnerability in c (CVE-2016-9843). Successful exploitation can lead to full system takeover.
|
| CVE-2016-9840 |
|
Vulnerability in c (CVE-2016-9840)
vulnerability in c (CVE-2016-9840). Successful exploitation can lead to full system takeover.
|
| CVE-2016-9842 |
|
Vulnerability in c (CVE-2016-9842)
vulnerability in c (CVE-2016-9842). Successful exploitation can lead to full system takeover.
|
| CVE-2016-7055 |
|
Vulnerability in openssl (CVE-2016-7055)
vulnerability in openssl (CVE-2016-7055). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-3731 |
|
Out-of-Bounds Read in openssl (CVE-2017-3731)
vulnerability in openssl (CVE-2017-3731). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-3732 |
|
Information Disclosure in openssl (CVE-2017-3732)
vulnerability in openssl (CVE-2017-3732). Confidential information can be exposed externally.
|
| CVE-2013-7454 |
|
Cross-Site Scripting (XSS) in nodejs (CVE-2013-7454)
cross-site scripting in nodejs (CVE-2013-7454). Risk of unauthorized operations or information disclosure.
|
| CVE-2013-7453 |
|
Cross-Site Scripting (XSS) in nodejs (CVE-2013-7453)
cross-site scripting in nodejs (CVE-2013-7453). Risk of unauthorized operations or information disclosure.
|
| CVE-2013-7452 |
|
Cross-Site Scripting (XSS) in nodejs (CVE-2013-7452)
cross-site scripting in nodejs (CVE-2013-7452). Risk of unauthorized operations or information disclosure.
|
| CVE-2013-7451 |
|
Cross-Site Scripting (XSS) in nodejs (CVE-2013-7451)
cross-site scripting in nodejs (CVE-2013-7451). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-9772 |
|
Cross-Site Scripting (XSS) in nodejs (CVE-2014-9772)
cross-site scripting in nodejs (CVE-2014-9772). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-8855 |
|
Vulnerability in dos (CVE-2015-8855)
vulnerability in dos (CVE-2015-8855). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-8860 |
|
Vulnerability in nodejs (CVE-2015-8860)
vulnerability in nodejs (CVE-2015-8860). Data can be tampered with by attackers.
|
| CVE-2016-2183 |
|
Information Disclosure in redhat (CVE-2016-2183)
vulnerability in redhat (CVE-2016-2183). Confidential information can be exposed externally.
|