Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Multer HIGH 7.5
CVE-2026-5038

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malfor…

Fix: 2.2.0+
Fix from $1,950 2026-06-15
Multer HIGH 7.5
CVE-2026-5079

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form d…

Fix: 2.2.0+
Fix from $1,950 2026-06-15
Multer HIGH 7.5
CVE-2026-3520

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a D…

Fix: 2.1.1+
Fix from $1,950 2026-03-04
Multer HIGH 7.5
CVE-2026-3304

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a D…

Fix: 2.1.0+
Fix from $1,950 2026-02-27
Multer HIGH 7.5
CVE-2026-2359

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a D…

Fix: 2.1.0+
Fix from $1,950 2026-02-27
Basic Auth Connect MEDIUM 5.3
CVE-2024-47178

basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can…

Fix: 1.1.0+
Fix from $1,600 2024-09-30
Method Override HIGH 7.5
CVE-2017-16136

method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't suppo…

Fix: 2.3.10+
Fix from $1,950 2018-06-07