Vulnerabilities
Summary — last 7 days
New vulnerabilities2,584▼ 301 vs. last week
Critical / high1,355▲ 100 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.5) | 0.52% | — | Node-staticAINubosoftware Node-staticAI | 9/30/2025 | 6/17/2026 | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server. | |
| Modified | High (7.5) | 1.4% | — | @nubosoftware/node-static Project @nubosoftware/node-staticNode-static Project Node-static | 3/6/2023 | 6/17/2026 | All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function. |