Known vulnerabilities in Node.js - page 8

Software: Node.js
Software CPE: cpe:2.3:a:node_js_foundation:nodejs:*:*:*:*:*:*:*:*
Total vulnerabilities: 172
Public exploits: 11
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Node.js Node.js is affected by 172 known vulnerabilities: 11 high, 108 medium, 53 low Critical High Medium Low

Vulnerabilities (172)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU26292 - Resource Management Errors
CVE-2019-5739
CWE-399 Medium
No
No
6.17.0 21.03.2020 SB2019032825
SB2020032103
SB2019040816
and 1 more
#VU16171 - Improper input validation
CVE-2018-12116
CWE-20 Low
No
No
6.15.0, 8.14.0, 11.3.0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 4 more
#VU16170 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2018-12123
CWE-451 Low
No
No
6.15.0, 8.14.0, 10.14.0, 11.3.0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 5 more
#VU16169 - Resource exhaustion
CVE-2018-12122
CWE-400 Low
No
No
6.15.0, 8.14.0, 10.14.0, 11.3.0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 5 more
#VU16168 - Heap-based Buffer Overflow
CVE-2018-12121
CWE-122 Low
No
No
6.15.0, 8.14.0, 10.14.0, 11.3.0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 8 more
#VU16167 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-12120
CWE-79 Low
No
No
6.15.0 29.11.2018 SB2018112906
SB2019012702
SB2019022215
and 1 more
#VU15723 - Information Exposure Through Timing Discrepancy
CVE-2018-5407
CWE-208 Low
Available
No
6.15.0, 8.14.0, 10.9 06.11.2018 SB2018110602
SB2018111301
SB2018112201
and 30 more
#VU15668 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0734
CWE-200 Low
No
No
10.14.0, 11.3.0 01.11.2018 SB2018110102
SB2018112201
SB2018112602
and 39 more
#VU15568 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0735
CWE-200 Low
No
No
6.15.0, 8.14.0, 10.14.0, 11.3.0 29.10.2018 SB2018110102
SB2018112602
SB2018112906
and 8 more
#VU14498 - Out-of-bounds write
CVE-2018-12115
CWE-787 Low
No
No
6.14.4, 8.11.4, 10.9 22.08.2018 SB2018082209
SB2018082313
SB2018082315
and 7 more
#VU14493 - Exposure of sensitive information to an unauthorized actor
CVE-2018-7166
CWE-200 Low
No
No
- 21.08.2018 SB2018082209
SB2019041743
#VU13379 - Improper input validation
CVE-2018-7167
CWE-20 Low
No
No
10.4.1 18.06.2018 SB2018061803
SB2018071402
SB2018071403
and 5 more
#VU13378 - Resource exhaustion
CVE-2018-7164
CWE-400 Low
No
No
10.4.1 18.06.2018 SB2018061803
SB2020032103
#VU13377 - Improper input validation
CVE-2018-7162
CWE-20 Low
No
No
10.4.1 18.06.2018 SB2018061803
SB2020032103
SB2018061524
and 2 more
#VU13376 - Improper input validation
CVE-2018-7161
CWE-20 Low
No
No
10.4.1 16.06.2018 SB2018061803
SB2018071402
SB2020032103
and 4 more
#VU31290 - Exposure of sensitive information to an unauthorized actor
CVE-2017-16024
CWE-200 Medium
No
No
0.11.9 04.06.2018 SB2018060421
#VU12575 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2018-7159
CWE-113 Low
No
No
- 10.05.2018 SB2018051406
SB2019080616
SB2020042404
and 8 more
#VU12573 - Resource exhaustion
CVE-2018-7158
CWE-400 Medium
No
No
- 10.05.2018 SB2018051406
SB2018033043
SB2018032834
and 6 more
#VU33508 - Exposure of sensitive information to an unauthorized actor
CVE-2017-15897
CWE-200 Low
No
No
- 11.12.2017 SB20171211323
SB2017120905
#VU33773 - Improper input validation
CVE-2017-15896
CWE-20 High
No
No
- 11.12.2017 SB20171211326
SB2017120904


Showing elements 141 - 160 out of 172