Vulnerabilities
Summary — last 7 days
New vulnerabilities3,142▲ 566 vs. last week
Critical / high1,456▲ 54 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)301▲ 287 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 4.0% | — | Gitlogplus Project Gitlogplus | 7/23/2021 | 6/17/2026 | All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization. | |
| Modified | Critical (9.8) | 5.4% | — | Gitlog Project Gitlog | 2/8/2021 | 6/17/2026 | The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability. |