VYPR
Vendor

ESM

Products
2
CVEs
8
Across products
8
Status
Private

Products

2

Recent CVEs

8
  • CVE-2024-11482CriNov 29, 2024
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

  • CVE-2024-11481HigNov 29, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.

  • CVE-2025-65025HigNov 19, 2025
    risk 0.46cvss 8.2epss 0.01

    esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarball extraction. An attacker can craft a malicious NPM package containing specially crafted file paths…

  • CVE-2026-27730HigFeb 25, 2026
    risk 0.42cvss 7.5epss 0.00

    esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm.sh’s `/http(s)` fetch route. The service tries to block localhost/internal targets, but the validation is based on hostname…

  • CVE-2025-50180HigFeb 25, 2026
    risk 0.42cvss 7.5epss 0.00

    esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.

  • CVE-2026-23644HigJan 18, 2026
    risk 0.42cvss 7.5epss 0.00

    esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerability due to an incomplete fix. `path.Clean` normalizes a path but does not prevent absolute paths in…

  • CVE-2025-65026MedNov 19, 2025
    risk 0.33cvss 6.1epss 0.00

    esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Literal Injection vulnerability (CWE-94) in its CSS-to-JavaScript module conversion feature. When a CSS file is requested with the…

  • CVE-2023-6070MedNov 29, 2023
    risk 0.28cvss 4.3epss 0.00

    A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts…