Known vulnerabilities in node-XMLHttpRequest
Vendor:
Michael de Wit
Software:
node-XMLHttpRequest
Software CPE:
cpe:2.3:a:mjwwit:xmlhttprequest-ssl:*:*:*:*:*:*:*:*
Website:
https://github.com/mjwwit
Total vulnerabilities:
2
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.9
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU76190 - Improper Certificate Validation CVE-2021-31597 |
CWE-295 | Medium | 1.6.1 | 16.05.2023 |
SB2021042338 SB2021091540 SB2021062325 and 1 more |
||
| #VU76189 - Improper Control of Generation of Code ('Code Injection') CVE-2020-28502 |
CWE-94 | Medium | 2.0.0 | 16.05.2023 |
SB2021030515 SB2021091541 SB2021061731 |