ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-23380
This affects all versions of package roar-pidusage.

This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operating systems, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

NVD description · AI analysis pending
7.31% PoC
  • roar-pidusage project roar-pidusage
CVE-2017-1000220
soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution

soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution

NVD description · AI analysis pending
9.85% PoC
  • pidusage project pidusage