open-flaw
9 exploits
Active since Jul 2017
Node.js 20.x 22.x 24.x 25.x - Denial of Service via __proto__ Header Handling
CVSS 7.5
Node.js 4.0-4.8.3 5.x 6.0-6.11.0 7.0-7.10.0 8.0-8.1.3 - Denial of Service via Hash Flooding
CVSS 7.5
TypeORM <0.2.25 - Prototype Pollution
CVSS 9.8
TypeORM < 0.3.0 - SQL Injection via FindOneOptions Parameter
CVSS 9.8
React Server Components <19.2.0 - RCE
CVSS 10.0
Node.js 20.x 22.x 24.x 25.x - Denial of Service via V8 String Hash Collision
CVSS 5.9
Redis < 6.2.20, 8.2.1-8.2.2 - Authenticated Use-After-Free via Lua Script Garbage Collector Manipulation
CVSS 9.9
mongoose < 6.13.6 and 8.0.0-rc0-8.9.5 - Search Injection via Nested $where Filter with Populate Match
CVSS 9.0
Package Validator <13.15.22 - Incomplete Filtering
CVSS 7.5