Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sequelize HIGH 7.5
CVE-2026-30951

Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverse…

Fix: 6.37.8+
Fix from $1,950 2026-03-10
Sequelize Typescript HIGH 7.1
CVE-2023-6293

Prototype Pollution in GitHub repository robinbuschmann/sequelize-typescript prior to 2.1.6.

Fix: 2.1.6+
Fix from $1,950 2023-11-24
Sequelize CRITICAL 9.8
CVE-2023-25813

Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed thro…

Fix: 6.19.1+
Fix from $2,300 2023-02-22
Sequelize CRITICAL 9.8
CVE-2023-22578

Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.

Fix: 6.29.0+
Fix from $2,300 2023-02-16
Sequelize HIGH 8.8
CVE-2023-22579

Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.

Fix: 6.28.1+
Fix from $1,950 2023-02-16
Sequelize HIGH 7.5
CVE-2023-22580

Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.

Fix: 6.28.1+
Fix from $1,950 2023-02-16
Sequelize CRITICAL 9.8
CVE-2019-10748

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the M…

Fix: 3.35.1 / 4.44.3+
Fix from $2,300 2019-10-29
Sequelize CRITICAL 9.8
CVE-2019-10749

sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres di…

Fix: 3.35.1+
Fix from $2,300 2019-10-29
Sequelize CRITICAL 9.8
CVE-2019-10752

Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping value…

Fix: 4.44.3 / 5.15.1+
Fix from $2,300 2019-10-17
Sequelize HIGH 7.5
CVE-2019-11069

Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.

Fix: 5.3.0+
Fix from $1,950 2019-04-10
Sequelize CRITICAL 9.8
CVE-2016-10554

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usabl…

Fix: after 1.6.0
Fix from $2,300 2018-05-31
Sequelize CRITICAL 9.8
CVE-2016-10550

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usabl…

Fix: after 3.16.0
Fix from $2,300 2018-05-31
Sequelize CRITICAL 9.8
CVE-2016-10553

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usabl…

Fix: after 2.1.3
Fix from $2,300 2018-05-31
Sequelize HIGH 7.5
CVE-2016-10556

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usabl…

Fix: after 3.19.3
Fix from $1,950 2018-05-29