VYPR

Vendor CVEs

Lumiverse

All CVEs

83 total · sorted by risk
  • CVE-2019-16775HigDec 13, 2019
    risk 0.43cvss 7.7epss 0.03

    Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would…

  • CVE-2024-36527MedJun 17, 2024
    risk 0.42cvss 6.5epss 0.03

    puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server.

  • CVE-2022-29244HigJun 13, 2022
    risk 0.42cvss 7.5epss 0.04

    npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively,…

  • CVE-2020-7684HigJul 17, 2020
    risk 0.42cvss 7.5epss 0.01

    This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.

  • CVE-2024-38990MedJul 1, 2024
    risk 0.41cvss 6.3epss 0.00

    Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2020-7788HigDec 11, 2020
    risk 0.41cvss 7.3epss 0.04

    This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

  • CVE-2020-7747MedOct 20, 2020
    risk 0.41cvss 6.3epss 0.01

    This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.

  • CVE-2026-47903MedJun 9, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does…

  • CVE-2019-19466MedDec 5, 2019
    risk 0.40cvss 6.1epss 0.01

    SCEditor 2.1.3 allows XSS.

  • CVE-2018-20524MedDec 27, 2018
    risk 0.40cvss 6.1epss 0.01

    The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of < in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).

  • CVE-2018-17046MedSep 14, 2018
    risk 0.40cvss 6.1epss 0.01

    translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.

  • CVE-2017-16087higMay 29, 2019
    risk 0.38cvss epss

    ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-wp3j-gv53-4pg8. This link is maintained to preserve external references. ## Original Description Affected versions of `fs-git` do not sanitize strings passed into the `buildCommand` method,…

  • CVE-2026-11232MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)

  • CVE-2021-23411MedJul 21, 2021
    risk 0.35cvss 5.4epss 0.01

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction.

  • CVE-2020-7779MedNov 26, 2020
    risk 0.35cvss 5.3epss 0.02

    All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!.

  • CVE-2020-7618MedApr 7, 2020
    risk 0.35cvss 5.3epss 0.01

    sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.

  • CVE-2020-7616MedApr 7, 2020
    risk 0.35cvss 5.3epss 0.01

    express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack…

  • CVE-2018-10178MedApr 17, 2018
    risk 0.35cvss 5.3epss 0.01

    The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisitedSites command.

  • CVE-2014-125128MedSep 8, 2025
    risk 0.33cvss 6.1epss 0.00

    'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (``), allowing bypasses that contain different casings, whitespace characters, or…

  • CVE-2015-9286MedApr 30, 2019
    risk 0.33cvss 6.1epss 0.01

    Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.

  • CVE-2015-9282MedFeb 6, 2019
    risk 0.33cvss 6.1epss 0.01

    The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.

  • CVE-2026-44443MedMay 26, 2026
    risk 0.31cvss 4.8epss 0.00

    Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's…

  • CVE-2024-25503MedApr 4, 2024
    risk 0.31cvss 4.7epss 0.01

    Cross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the edit details parameter of the New Project function.

  • CVE-2026-53606MedJun 12, 2026
    risk 0.28cvss 5.4epss 0.00

    ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 use `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the…

  • CVE-2026-9467MedMay 25, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and…

  • CVE-2022-25869MedJul 15, 2022
    risk 0.28cvss 4.2epss 0.07

    All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of elements.

  • CVE-2020-7696MedJul 17, 2020
    risk 0.28cvss 5.3epss 0.02

    This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session…

  • CVE-2016-1000224medSep 1, 2020
    risk 0.26cvss epss 0.00

    Affected versions of `ezseed-transmission` download and run a script over an HTTP connection. An attacker in a privileged network position could launch a Man-in-the-Middle attack and intercept the script, replacing it with malicious code, completely compromising the system…

  • CVE-2014-8881medSep 1, 2020
    risk 0.26cvss epss 0.02

    All versions of the `bleach` package are vulnerable to a regular expression denial of service attack when certain types of input are passed into the sanitize function. ## Recommendation The `bleach` package is not currently maintained, and has not seen an update since 2014. …

  • CVE-2014-8883medAug 31, 2020
    risk 0.26cvss epss 0.01

    All versions of the static file server module nhouston are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory. ## Recommendation It is recommended that a different module be used, as we have been unable…

  • CVE-2020-15095MedJul 7, 2020
    risk 0.22cvss 4.4epss 0.00

    Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and…

  • CVE-2026-11686LowJun 9, 2026
    risk 0.20cvss 3.1epss 0.00

    Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2020-28448MedDec 22, 2020
    risk 0.00cvss 5.6epss 0.01

    This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.

Page 2 of 2