VYPR

apk package

chainguard/wazuh-dashboard-security-plugin

pkg:apk/chainguard/wazuh-dashboard-security-plugin

Vulnerabilities (27)

  • CVE-2026-34601HigApr 2, 2026
    affected < 4.14.6-r3fixed 4.14.6-r3

    xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator

  • CVE-2026-4867HigMar 26, 2026
    affected < 4.14.6-r4fixed 4.14.6-r4

    Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in [email protected] only prevents ambigu

  • CVE-2022-39353CriNov 2, 2022
    affected < 4.14.6-r3fixed 4.14.6-r3

    xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root nodes to the `childNodes` collection of the `Document`, witho

  • CVE-2022-31129HigJul 6, 2022
    affected < 4.14.6-r5fixed 4.14.6-r5

    moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried

  • CVE-2022-24785HigApr 4, 2022
    affected < 4.14.6-r5fixed 4.14.6-r5

    Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch mom

  • CVE-2021-32796MedJul 27, 2021
    affected < 4.14.6-r3fixed 4.14.6-r3

    xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syn

  • CVE-2021-21366MedMar 12, 2021
    affected < 4.14.6-r3fixed 4.14.6-r3

    xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly parsing and serializing maliciously crafted documents. This m

Page 2 of 2