Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Systeminformation HIGH 8.8
CVE-2026-50289

systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injec…

Fix: 5.31.7+
Fix from $1,950 2026-07-17
Systeminformation HIGH 8.8
CVE-2026-26318

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `l…

Fix: 5.31.0+
Fix from $1,950 2026-02-19
Systeminformation HIGH 7.8
CVE-2026-26280

systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetw…

Fix: 5.30.8+
Fix from $1,950 2026-02-19
Systeminformation HIGH 8.1
CVE-2025-68154EPSS 13%

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is v…

Fix: 5.27.14+
Fix from $1,950 2025-12-16
Systeminformation CRITICAL 9.8
CVE-2023-42810

systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem…

Fix: 5.21.7+
Fix from $2,300 2023-09-21
Systeminformation CRITICAL 9.8
CVE-2020-26300

systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is …

Fix: 4.26.2+
Fix from $2,300 2021-09-09
Systeminformation CRITICAL 9.8
CVE-2021-21388

systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions …

Fix: 5.6.4+
Fix from $2,300 2021-04-29
Systeminformation HIGH 8.8
CVE-2020-26274

In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a s…

Fix: 4.31.1+
Fix from $1,950 2020-12-16
Systeminformation CRITICAL 9.8
CVE-2020-26245

npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rew…

Fix: 4.30.5+
Fix from $2,300 2020-11-27
Systeminformation HIGH 7.3
CVE-2020-7778

This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to exe…

Fix: 4.30.2+
Fix from $1,950 2020-11-26
Systeminformation HIGH 8.8
CVE-2020-7752EPSS 6%

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's param…

Fix: 4.27.11+
Fix from $1,950 2020-10-26