nodejs
219 tracked vulnerabilities.
CVE-2020-8172
HIGH
Node <12.18.0-14.4.0 - SSL/TLS Verification Bypass
Jun 08, 2020
CVSS 7.4
EPSS 0.01
CVE-2020-11080
LOW
nghttp2 < 1.41.0 - Denial of Service via Large HTTP/2 SETTINGS Frame Payload
Jun 03, 2020
CVSS 3.7
EPSS 0.01
CVE-2020-10531
HIGH
International Components for Unicode < 66.1 - Heap-Based Buffer Overflow via UnicodeString::doAppend() Integer Overflow
Mar 12, 2020
CVSS 8.8
EPSS 0.01
CVE-2019-15606
CRITICAL
Node.js 10.0.0-10.18.1, 13.0.0-13.7.0 - Authorization Bypass via HTTP Header Trailing Whitespace
Feb 07, 2020
CVSS 9.8
EPSS 0.01
CVE-2019-15605
CRITICAL
Node.js 10.0.0-10.18.9, 13.0.0-13.7.0 - HTTP Request Smuggling via Malformed Transfer-Encoding
Feb 07, 2020
CVSS 9.8
EPSS 0.32
CVE-2019-15604
HIGH
Node.js 10.0.0-10.18.9, 13.0.0-13.7.9 - Denial of Service via Crafted X.509 Certificate
Feb 07, 2020
CVSS 7.5
EPSS 0.04
CVE-2019-9518
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Empty Frame Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.04
CVE-2019-9517
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Window Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.05
CVE-2019-9516
MEDIUM
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Header Leak
Aug 13, 2019
CVSS 6.5
EPSS 0.02
CVE-2019-9515
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Settings Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.09
CVE-2019-9514
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Reset Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.10
CVE-2019-9513
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Priority Tree Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.07
CVE-2019-9512
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Ping Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.52
CVE-2019-9511
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Window Size Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.14
CVE-2019-5739
HIGH
Node.js < 6.16.0 - Denial of Service via Keep-Alive Timeout
Mar 28, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-5737
HIGH
Node.js 6.x < 6.17.0, 8.x < 8.15.1, 10.x < 10.15.2, 11.x < 11.10.1 - Denial of Service via Slow HTTP Headers
Mar 28, 2019
CVSS 7.5
EPSS 0.26
CVE-2019-1559
MEDIUM
OpenSSL 1.0.2-1.0.2q - Padding Oracle via SSL_shutdown Double Call
Feb 27, 2019
CVSS 5.9
EPSS 0.05
CVE-2018-21270
MEDIUM
Node.js stringstream < 0.0.6 - Out-of-bounds Read via Uninitialized Buffer Allocation
Dec 03, 2020
CVSS 6.5
EPSS 0.01
CVE-2018-12123
MEDIUM
Node.js <6.15.0, 8.14.0, 10.14.0, 11.3.0 - Info Disclosure
Nov 28, 2018
CVSS 4.3
EPSS 0.04
CVE-2018-12122
HIGH
Node.js <6.15.0, 8.14.0, 10.14.0, 11.3.0 - DoS
Nov 28, 2018
CVSS 7.5
EPSS 0.02
CVE-2018-12121
HIGH
Node.js <6.15.0,8.14.0,10.14.0,11.3.0 - DoS
Nov 28, 2018
CVSS 7.5
EPSS 0.06
CVE-2018-12120
HIGH
Node.js 6.0.0-6.14.9 - Remote Code Execution via Debugger Port
Nov 28, 2018
CVSS 8.1
EPSS 0.00
CVE-2018-12116
HIGH
Node.js < 6.8.1 and 6.9.0-6.15.0 - HTTP Request Splitting via Path Option
Nov 28, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-5407
MEDIUM
Ubuntu Linux - Exposure of Sensitive Information via SMT Port Contention Timing Attack
Nov 15, 2018
CVSS 4.7
EPSS 0.01
CVE-2018-0734
MEDIUM
OpenSSL 1.0.2-1.0.2p 1.1.0-1.1.0i 1.1.1 - Timing Side Channel Attack via DSA Signature Algorithm
Oct 30, 2018
CVSS 5.9
EPSS 0.05
Products
Quick Filters