Valeri Karpov
7 exploits
Active since Oct 2019
mongoosejs/mongoose < 6.13.5 and >=8.0.0-rc0 <8.8.3 - Search Injection via $where in Match
CVSS 9.1
mongoose < 6.13.6 and 8.0.0-rc0-8.9.5 - Search Injection via Nested $where Filter with Populate Match
CVSS 9.0
Automattic Mongoose <5.7.4 - Auth Bypass
CVSS 9.1
mquery < 3.2.3 - Prototype Pollution via Merge/Clone Operation
CVSS 5.3
mpath < 0.8.4 - Type Confusion via Array IndexOf Bypass
CVSS 5.6
automattic/mongoose <6.4.6 - Info Disclosure
CVSS 9.8
mongoose < 5.13.20 and 7.0.0-7.3.3 - Prototype Pollution
CVSS 9.8