Known vulnerabilities in Node.js - page 5

Software: Node.js
Software CPE: cpe:2.3:a:node_js_foundation:nodejs:*:*:*:*:*:*:*:*
Total vulnerabilities: 172
Public exploits: 11
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Node.js Node.js is affected by 172 known vulnerabilities: 11 high, 108 medium, 53 low Critical High Medium Low

Vulnerabilities (172)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77606 - Inconsistency Between Implementation and Documented Design
CVE-2023-30590
CWE-1068 Medium
No
No
16.20.1, 18.16.1, 20.3.1 21.06.2023 SB2023062144
SB2023062727
SB2023062743
and 33 more
#VU77605 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-30589
CWE-444 Medium
No
No
16.20.1, 18.16.1, 20.3.1 21.06.2023 SB2023062144
SB2023062727
SB2023062743
and 43 more
#VU77604 - Improper input validation
CVE-2023-30588
CWE-20 Medium
No
No
16.20.1, 18.16.1, 20.3.1 21.06.2023 SB2023062144
SB2023062727
SB2023062743
and 33 more
#VU77603 - Permissions, Privileges, and Access Controls
CVE-2023-30586
CWE-264 Medium
No
No
20.3.1 21.06.2023 SB2023062144
SB2023072539
SB2023082320
and 6 more
#VU77601 - Untrusted Search Path
CVE-2023-30585
CWE-426 Low
No
No
16.20.1, 18.16.1, 20.3.1 21.06.2023 SB2023062144
SB2023062727
SB2023062743
and 13 more
#VU77599 - Permissions, Privileges, and Access Controls
CVE-2023-30583
CWE-264 Low
No
No
20.3.1 21.06.2023 SB2023062144
SB2023072539
SB2023082320
and 6 more
#VU77596 - Permissions, Privileges, and Access Controls
CVE-2023-30582
CWE-264 Low
No
No
20.3.1 21.06.2023 SB2023062144
SB2023072539
SB2023082320
and 6 more
#VU77595 - Improper Access Control
CVE-2023-30587
CWE-284 Medium
No
No
20.3.1 21.06.2023 SB2023062144
SB2023072539
SB2023082320
and 7 more
#VU76426 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2023-31147
CWE-338 Medium
No
No
16.20.1, 18.16.1, 20.3.1 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 39 more
#VU76425 - Buffer Underwrite ('Buffer Underflow')
CVE-2023-31130
CWE-124 Low
No
No
16.20.1, 18.16.1, 20.3.1 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 55 more
#VU76424 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2023-31124
CWE-338 Medium
No
No
16.20.1, 18.16.1, 20.3.1 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 33 more
#VU76423 - Improper input validation
CVE-2023-32067
CWE-20 Medium
No
No
16.20.1, 18.16.1, 20.3.1 23.05.2023 SB2023052312
SB2023053021
SB2023060711
and 35 more
#VU71999 - NULL Pointer Dereference
CVE-2023-0401
CWE-476 Medium
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 52 more
#VU71998 - NULL Pointer Dereference
CVE-2023-0217
CWE-476 Medium
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 49 more
#VU71997 - Release of invalid pointer or reference
CVE-2023-0216
CWE-763 Medium
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 50 more
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71994 - Out-of-bounds read
CVE-2022-4203
CWE-125 Medium
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 47 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more


Showing elements 81 - 100 out of 172