zodiac12

1 exploit Active since Jul 2020
CVE-2020-7699 NOMISEC HIGH WORKING POC
express-fileupload < 1.1.8 - Denial of Service and Remote Code Execution via Corrupt HTTP Request
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
CVSS 7.5