Ulises Gascón
8 exploits
Active since Sep 2024
serve-static < 1.16.0 - Cross-Site Scripting via Unsanitized User Input in redirect()
CVSS 5.0
body-parser < 1.20.3 - Denial of Service via URL Encoding
CVSS 7.5
Express < 4.20.0 - Cross-Site Scripting via response.redirect()
CVSS 5.0
send < 0.19.0 - Cross-Site Scripting via SendStream.redirect()
CVSS 5.0
serve-static < 1.16.0 - Cross-Site Scripting via Unsanitized User Input in redirect()
CVSS 5.0
basic-auth-connect <1.1.0 - Info Disclosure
CVSS 5.3
Multer < 2.0.0 - Denial of Service via Unclosed Stream Handling
CVSS 7.5
multer 1.4.4-lts.1-2.0.0 - Denial of Service via Malformed Multi-Part Upload Request
CVSS 7.5