CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-1243MEDIUM | CRHTLF can lead to invalid protocol extraction potentially leading to XSS in medialize/uri.jsCRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11. CWE-20Apr 5, 2022 | CVSS6.1v3.1 | EPSS0.663% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1233MEDIUM | URL Confusion When Scheme Not Supplied in medialize/uri.jsURL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11. | CVSS6.1v3.1 | EPSS0.787% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0868MEDIUM | Open Redirect in medialize/uri.jsOpen Redirect in GitHub repository medialize/uri.js prior to 1.19.10. CWE-601Mar 6, 2022 | CVSS6.1v3.1 | EPSS0.719% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0613MEDIUM | Authorization Bypass Through User-Controlled Key in medialize/uri.jsAuthorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. CWE-639Feb 16, 2022 | CVSS6.5v3.1 | EPSS1.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-3647MEDIUM | Open Redirect in medialize/URI.jsURI.js is vulnerable to URL Redirection to Untrusted Site CWE-601Jul 16, 2021 | CVSS6.1v3.1 | EPSS0.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |