ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35065
The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

NVD description · AI analysis pending
7.52% PoC ×2
  • gulpjs glob-parent
CVE-2020-28469
This affects the package glob-parent before 5.1.2.

This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.

NVD description · AI analysis pending
7.55% PoC ×3
  • gulpjs glob-parent
  • gulpjs communications cloud native core policy
CVE-2020-28503
The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.

The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.

NVD description · AI analysis pending
9.82% PoC ×2
  • gulpjs copy-props