Known Vulnerabilities for products from Express-fileupload Project
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Express-fileupload Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-27261 json | An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same na... | 7.5 - HIGH | 2022-04-12 | 2023-10-18 |
| CVE-2022-27140 json | ** DISPUTED ** An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers ... | 9.8 - CRITICAL | 2022-04-12 | 2023-12-15 |
| CVE-2020-7699 json | This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP reques... | 9.8 - CRITICAL | 2020-07-30 | 2022-12-02 |
Known software with vulnerabilities from Express-fileupload Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Express-fileupload Project | Express-fileupload | 0.0.6 |