Known vulnerabilities in url-parse 1.4.4
Vendor:
unshiftio
Software:
url-parse
Version:
1.4.4
Software CPE:
cpe:2.3:a:unshiftio:url-parse:*:*:*:*:*:*:*:*
Website:
https://unshift.io/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Vulnerabilities by Severity
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU74174 - Improper input validation CVE-2020-8124 |
CWE-20 | Medium | 1.4.5 | 29.03.2023 |
SB2020020444 SB2023032938 SB2024061009 and 1 more |
||
| #VU55484 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2021-3664 |
CWE-601 | Low | 1.5.2 | 02.08.2021 |
SB2021080206 SB2021082509 SB2023032938 and 3 more |
||
| #VU50868 - Exposure of sensitive information to an unauthorized actor CVE-2021-27515 |
CWE-200 | Medium | 1.5.0 | 23.02.2021 |
SB2021022310 SB2023032938 SB2024010530 and 2 more |