Vulnerabilities

Summary — last 7 days

New vulnerabilities3,142▲ 566 vs. last week
Critical / high1,456▲ 54 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)301▲ 287 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.8)4.0%—Gitlogplus Project Gitlogplus7/23/20216/17/2026
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
ModifiedCritical (9.8)5.4%—Gitlog Project Gitlog2/8/20216/17/2026
The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.
Orbitaley — Vulnerabilities