Vulnerabilities
Summary — last 7 days
New vulnerabilities2,732▼ 549 vs. last week
Critical / high1,295▼ 233 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)244▼ 258 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.3) | 1.2% | — | Roar-pidusage Project Roar-pidusage | 4/18/2021 | 6/17/2026 | This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operating systems, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | |
| Modified | Critical (9.8) | 5.1% | — | Pidusage Project Pidusage | 11/17/2017 | 6/17/2026 | soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution |