Vulnerabilities

Summary — last 7 days

New vulnerabilities2,528▼ 418 vs. last week
Critical / high1,311▲ 21 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)99▼ 428 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.5)0.47%—Jawherkl Node-api-postgresAI3/16/20266/17/2026
A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This manipulation causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor…
DeferredMedium (5.5)0.41%—Jawherkal Node-api-postgresAI3/16/20266/17/2026
A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about…
DeferredHigh (8.6)0.37%—DuckdbAIDuckdb Node-apiAIDuckdb Node-bindingsAIDuckdb-wasmAI9/9/20256/17/2026
DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interfere with cryptocoin…