Vulnerabilities

Summary — last 7 days

New vulnerabilities2,659▼ 692 vs. last week
Critical / high1,261▼ 300 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)250▼ 252 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.8)1.1%—Kill-process-by-name Project Kill-process-by-name3/15/20216/17/2026
This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization in the index.js file.
Orbitaley — Vulnerabilities