Vulnerabilities

Summary — last 7 days

New vulnerabilities2,584▼ 301 vs. last week
Critical / high1,355▲ 100 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.5)0.52%—Node-staticAINubosoftware Node-staticAI9/30/20256/17/2026
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.
ModifiedHigh (7.5)1.4%—@nubosoftware/node-static Project @nubosoftware/node-staticNode-static Project Node-static3/6/20236/17/2026
All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.