Known vulnerabilities in nodejs-npm - page 2

Vendor: OpenAnolis
Software: nodejs-npm
Software CPE: cpe:2.3:o:openanolis:nodejs-npm:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 27
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting nodejs-npm nodejs-npm is affected by 27 known vulnerabilities: 2 high, 15 medium, 10 low Critical High Medium Low

Vulnerabilities (27)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126386 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-55131
CWE-362 Low
No
No
10.9.4-1.22.22.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 20 more
#VU126387 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-55130
CWE-59 Low
No
No
10.9.4-1.22.22.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 17 more
#VU126388 - Uncaught Exception
CVE-2025-59465
CWE-248 Medium
No
No
10.9.4-1.22.22.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 23 more
#VU126392 - Improper Access Control
CVE-2025-55132
CWE-284 Low
No
No
10.9.4-1.22.22.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 13 more
#VU124548 - Improper Access Control
CVE-2026-21715
CWE-284 Low
No
No
10.9.4-1.22.22.0.4 25.03.2026 SB20260325154
SB2026032902
SB2026041564
and 18 more
#VU124542 - Error Handling
CVE-2026-21710
CWE-388 Medium
No
No
10.9.4-1.22.22.0.2 25.03.2026 SB20260325154
SB2026032902
SB2026041056
and 33 more
#VU124545 - Information Exposure Through Timing Discrepancy
CVE-2026-21713
CWE-208 Medium
No
No
10.9.4-1.22.22.0.3 25.03.2026 SB20260325154
SB2026032902
SB2026041543
and 22 more


Showing elements 21 - 40 out of 27