Vulnerabilities

Summary — last 7 days

New vulnerabilities2,768▲ 15 vs. last week
Critical / high1,274▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.5)0.37%—Link-preview-js Project Link-preview-js7/1/20226/17/2026
The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.
Orbitaley — Vulnerabilities