Software
node.js
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
60
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2014-7192 | 10.0 | HIGH | Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other pr... |
| CVE-2015-0278 | 10.0 | HIGH | libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors. |
| CVE-2026-21636 | 10.0 | N/A | A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--... |
| CVE-2015-6764 | 9.8 | N/A | The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, im... |
| CVE-2016-5180 | 9.8 | N/A | Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds wri... |
| CVE-2016-6303 | 9.8 | N/A | Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-boun... |
| CVE-2016-9841 | 9.8 | N/A | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
| CVE-2016-9843 | 9.8 | N/A | The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculat... |
| CVE-2019-15605 | 9.8 | N/A | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed |
| CVE-2019-15606 | 9.8 | N/A | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons |
| CVE-2021-22930 | 9.8 | N/A | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change... |
| CVE-2021-22931 | 9.8 | N/A | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names retur... |
| CVE-2023-32002 | 9.8 | N/A | The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability af... |
| CVE-2023-39332 | 9.8 | N/A | Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the `Uint8Arra... |
| CVE-2024-21896 | 9.8 | N/A | The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a... |
| CVE-2024-3566 | 9.8 | N/A | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when... |
| CVE-2016-9841 | 9.8 | N/A | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
| CVE-2026-48930 | 9.8 | N/A | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.... |
| CVE-2017-15896 | 9.1 | N/A | Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active netw... |
| CVE-2022-35255 | 9.1 | N/A | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/cr... |
| CVE-2025-55130 | 9.1 | N/A | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By... |
| CVE-2025-55130 | 9.1 | N/A | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By... |
| CVE-2025-55130 | 9.1 | N/A | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By... |
| CVE-2016-1669 | 8.8 | N/A | The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certa... |
| CVE-2016-9840 | 8.8 | N/A | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
| CVE-2016-9842 | 8.8 | N/A | The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of nega... |
| CVE-2018-7160 | 8.8 | N/A | The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible... |
| CVE-2020-10531 | 8.8 | N/A | An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exis... |
| CVE-2023-32004 | 8.8 | N/A | A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buff... |
| CVE-2023-32006 | 8.8 | N/A | The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. T... |
| CVE-2024-21891 | 8.8 | N/A | Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementatio... |
| CVE-2016-9840 | 8.8 | N/A | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
| CVE-2016-9842 | 8.8 | N/A | The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of nega... |
| CVE-2022-21824 | 8.2 | N/A | Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while si... |
| CVE-2014-9748 | 8.1 | N/A | The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other... |
| CVE-2018-12120 | 8.1 | N/A | Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node... |
| CVE-2020-8174 | 8.1 | N/A | napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0. |
| CVE-2020-8265 | 8.1 | N/A | Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket... |
| CVE-2022-32212 | 8.1 | N/A | A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypass... |
| CVE-2022-43548 | 8.1 | N/A | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily... |