Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Evershop HIGH 7.5
CVE-2025-65844

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint i…

No fix yet
Fix from $1,950 2025-12-02
Evershop CRITICAL 9.1
CVE-2023-46943

An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "se…

Mitigation only
Fix from $2,300 2024-01-13
Evershop HIGH 7.5
CVE-2023-46942

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via imp…

Mitigation only
Fix from $1,950 2024-01-13
Evershop CRITICAL 9.8
CVE-2023-46498

An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /de…

Mitigation only
Fix from $2,300 2023-12-08
Evershop HIGH 8.3
CVE-2023-46496

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted…

Mitigation only
Fix from $1,950 2023-12-08
Evershop MEDIUM 6.1
CVE-2023-46494

Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafte…

Mitigation only
Fix from $1,600 2023-12-08
Evershop MEDIUM 6.1
CVE-2023-46495

Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafte…

Mitigation only
Fix from $1,600 2023-12-08
Evershop MEDIUM 6.1
CVE-2023-46499

Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafte…

Mitigation only
Fix from $1,600 2023-12-08
Evershop MEDIUM 5.4
CVE-2023-46497

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted…

Mitigation only
Fix from $1,600 2023-12-08
Evershop MEDIUM 5.3
CVE-2023-46493

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted…

Mitigation only
Fix from $1,600 2023-12-08