NA - CVE-2024-8555 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown function of the file congratulations.php. The...
NA - CVE-2024-8557 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affects an unknown part of the file /foms/routers/cancel-order.php. The...
NA - CVE-2023-30582 - A vulnerability has been identified in Node.js...
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an...
NA - CVE-2023-30583 - fs.openAsBlob() can bypass the experimental...
fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the...
NA - CVE-2023-30584 - A vulnerability has been discovered in Node.js...
A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of path traversal bypass when verifying file...
NA - CVE-2023-30587 - A vulnerability in Node.js version 20 allows...
A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module (node:inspector). By exploiting the Worker...
NA - CVE-2023-39333 - Maliciously crafted export names in an imported...
Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not...
NA - CVE-2023-46809 - Node.js versions which bundle an unpatched...
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack -...
NA - CVE-2024-36137 - A vulnerability has been identified in Node.js,...
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file...
NA - CVE-2024-36138 - Bypass incomplete fix of CVE-2024-27980, that...
Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious...