Chris de Almeida
6 exploits
Active since Sep 2024
serve-static < 1.16.0 - Cross-Site Scripting via Unsanitized User Input in redirect()
CVSS 5.0
Express < 4.20.0 - Cross-Site Scripting via response.redirect()
CVSS 5.0
send < 0.19.0 - Cross-Site Scripting via SendStream.redirect()
CVSS 5.0
serve-static < 1.16.0 - Cross-Site Scripting via Unsanitized User Input in redirect()
CVSS 5.0
Multer < 2.0.0 - Denial of Service via Unclosed Stream Handling
CVSS 7.5
multer 1.4.4-lts.1-2.0.0 - Denial of Service via Malformed Multi-Part Upload Request
CVSS 7.5