Known vulnerabilities in Node.js - page 6

Software: Node.js
Software CPE: cpe:2.3:a:node_js_foundation:nodejs:*:*:*:*:*:*:*:*
Total vulnerabilities: 172
Public exploits: 11
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Node.js Node.js is affected by 172 known vulnerabilities: 11 high, 108 medium, 53 low Critical High Medium Low

Vulnerabilities (172)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU72404 - Incorrect Regular Expression
CVE-2023-24807
CWE-185 Medium
No
No
16.19.1, 18.14.1, 19.6.1 20.02.2023 SB2023022022
SB2023022020
SB2023030129
and 34 more
#VU72403 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-23936
CWE-113 Medium
No
No
16.19.1, 18.14.1, 19.6.1 20.02.2023 SB2023022022
SB2023022020
SB2023030129
and 35 more
#VU72400 - Permissions, Privileges, and Access Controls
CVE-2023-23920
CWE-264 Low
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 55 more
#VU72399 - Resource Management Errors
CVE-2023-23919
CWE-399 Medium
No
No
16.19.1, 18.14.1, 19.2.0 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 33 more
#VU72398 - Permissions, Privileges, and Access Controls
CVE-2023-23918
CWE-264 Medium
No
No
14.21.3, 16.19.1, 18.14.1, 19.6.1 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 48 more
#VU69354 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2022-43548
CWE-350 Medium
No
No
14.21.1, 16.18.1, 18.12.1, 19.0.1 15.11.2022 SB2022111599
SB20221115101
SB20221115102
and 47 more
#VU68896 - Memory corruption
CVE-2022-3786
CWE-119 Medium
Available
No
14.21.1, 16.18.1, 18.12.1, 19.0.1 01.11.2022 SB2022110132
SB2022110133
SB2022110144
and 44 more
#VU68895 - Memory corruption
CVE-2022-3602
CWE-119 High
Available
No
14.21.1, 16.18.1, 18.12.1, 19.0.1 01.11.2022 SB2022110132
SB2022110133
SB2022110144
and 45 more
#VU67850 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-35256
CWE-444 Medium
No
No
14.20.1, 16.17.1, 18.9.1 03.10.2022 SB2022100347
SB2022100401
SB2022100402
and 50 more
#VU67849 - Use of Insufficiently Random Values
CVE-2022-35255
CWE-330 Medium
No
No
14.20.1, 16.17.1, 18.9.1 03.10.2022 SB2022100401
SB2022100402
SB2022100528
and 40 more
#VU66698 - Exposure of sensitive information to an unauthorized actor
CVE-2022-29244
CWE-200 Medium
No
No
16.15.1, 17.9.1 22.08.2022 SB2022082252
SB2022082253
SB2022091110
and 15 more
#VU65282 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32215
CWE-444 Medium
No
No
14.20.0, 16.16.0, 18.5.0, 14.20.1, 16.17.1, 18.9.1 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 54 more
#VU65280 - Security Features
CVE-2022-32222
CWE-254 Medium
No
No
18.9.1 13.07.2022 SB2022071338
SB2022081105
SB2022100401
and 10 more
#VU65275 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32213
CWE-444 Medium
No
No
14.20.0, 16.16.0, 18.5.0, 14.20.1, 16.17.1, 18.9.1 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 55 more
#VU65273 - Improper Check or Handling of Exceptional Conditions
CVE-2022-32212
CWE-703 Medium
No
No
14.20.0, 16.16.0, 18.5.0, 14.20.1, 16.17.1, 18.9.1 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 48 more
#VU59551 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21824
CWE-94 Medium
No
No
12.22.9, 14.18.3, 16.13.2, 17.3.1 12.01.2022 SB2022011216
SB2022041205
SB2022060315
and 39 more
#VU59550 - Improper Certificate Validation
CVE-2021-44533
CWE-295 Medium
No
No
12.22.9, 14.18.3, 16.13.2, 17.3.1 12.01.2022 SB2022011216
SB2022041522
SB2022042517
and 36 more
#VU59549 - Improper Validation of Certificate with Host Mismatch
CVE-2021-44532
CWE-297 Medium
No
No
12.22.9, 14.18.3, 16.13.2, 17.3.1 12.01.2022 SB2022011216
SB2022041522
SB2022042806
and 36 more
#VU59548 - Improper Certificate Validation
CVE-2021-44531
CWE-295 Medium
No
No
12.22.9, 14.18.3, 16.13.2, 17.3.1 12.01.2022 SB2022011216
SB2022032010
SB2022041522
and 35 more
#VU12576 - Improper input validation
CVE-2018-7160
CWE-20 High
No
No
14.20.1, 16.17.1, 18.9.1 10.05.2018 SB2018051406
SB2018033045
SB2022031104
and 9 more


Showing elements 101 - 120 out of 172