Known vulnerabilities in rh-nodejs14-nodejs (Red Hat package) - page 3

Software CPE: cpe:2.3:o:red_hat:rh-nodejs14-nodejs_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 57
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rh-nodejs14-nodejs (Red Hat package) rh-nodejs14-nodejs (Red Hat package) is affected by 57 known vulnerabilities: 5 high, 48 medium, 4 low Critical High Medium Low

Vulnerabilities (57)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU76389 - Incorrect Regular Expression
CVE-2020-7754
CWE-185 Medium
No
No
14.15.4-2.el7 19.05.2023 SB2023051950
SB2022072231
SB2021020440
and 5 more
#VU63698 - Incorrect Regular Expression
CVE-2021-33502
CWE-185 Medium
No
No
14.17.2-1.el7 26.05.2022 SB2021052416
SB2022052615
SB2022060618
and 17 more
#VU61255 - Incorrect Regular Expression
CVE-2021-23362
CWE-185 Medium
No
No
14.17.2-1.el7 11.03.2022 SB2021032315
SB2022031104
SB2022060315
and 28 more
#VU61254 - Use After Free
CVE-2021-22940
CWE-416 Medium
No
No
14.17.5-1.el7 11.03.2022 SB2021081615
SB2022031104
SB2022060618
and 23 more
#VU61253 - Improper Certificate Validation
CVE-2021-22939
CWE-295 Medium
No
No
14.17.5-1.el7 11.03.2022 SB2021081614
SB2022031104
SB2022060618
and 25 more
#VU58206 - Absolute Path Traversal
CVE-2021-32803
CWE-36 Medium
No
No
14.17.5-1.el7 17.11.2021 SB2021080329
SB2022031104
SB2022060618
and 26 more
#VU57498 - Improper input validation
CVE-2021-22931
CWE-20 High
No
No
14.17.5-1.el7 19.10.2021 SB2021101945
SB2022020113
SB2022031104
and 28 more
#VU55498 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-15366
CWE-94 Medium
No
No
14.15.4-2.el7 02.08.2021 SB2020071552
SB2021080213
SB2020120120
and 14 more
#VU55315 - Incorrect Regular Expression
CVE-2021-23343
CWE-185 Medium
No
No
14.17.5-1.el7 26.07.2021 SB2021072624
SB2021072625
SB2022060618
and 24 more
#VU54624 - Out-of-bounds read
CVE-2021-22918
CWE-125 Medium
No
No
14.17.2-1.el7 08.07.2021 SB2021070819
SB2021072009
SB2021081123
and 40 more
#VU52909 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7774
CWE-94 Medium
No
No
14.15.4-2.el7 06.05.2021 SB2020111735
SB2021050615
SB2021092814
and 24 more
#VU52194 - Incorrect Regular Expression
CVE-2021-27290
CWE-185 Medium
No
No
14.17.2-1.el7 12.03.2021 SB2021041364
SB2021070819
SB2021101939
and 32 more
#VU50955 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2021-22884
CWE-350 Medium
No
No
14.16.0-1.el7 25.02.2021 SB2021022530
SB2021022532
SB2021022616
and 38 more
#VU50954 - Resource Management Errors
CVE-2021-22883
CWE-399 Medium
No
No
14.16.0-1.el7 25.02.2021 SB2021022530
SB2021022532
SB2021022614
and 36 more
#VU49254 - Use After Free
CVE-2020-8265
CWE-416 Medium
No
No
14.15.4-2.el7 04.01.2021 SB2021010419
SB2021010704
SB2021010705
and 33 more
#VU49253 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-8287
CWE-444 Medium
Available
No
14.15.4-2.el7 04.01.2021 SB2021010419
SB2021010706
SB2021010707
and 33 more
#VU48569 - Resource Management Errors
CVE-2020-8277
CWE-399 Medium
Available
No
14.15.4-2.el7 19.11.2020 SB2020112003
SB2020112005
SB2020102133
and 23 more


Showing elements 41 - 60 out of 57