Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-43308 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbi An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2022-24613 +1 in the same advisory: …24614 | metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2019-14262 | MetadataExtractor 2.1.0 allows stack consumption. MetadataExtractor 2.1.0 allows stack consumption. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2018-14063 | The increaseApproval function of a smart contract implementation for Tracto (TRCT), an Ethereum ERC20 token, has an integer overflow. The increaseApproval function of a smart contract implementation for Tracto (TRCT), an Ethereum ERC20 token, has an integer overflow. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2017-15968 | MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter. MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC ×2 |
| — |