📦

node.js

Vendor: nodejs

Actively Exploited 1 CISA KEV List
PoC / Exploits 22 Code Available
Total RCEs 16 Remote Access
Total CVEs 695 Total Indexed
Avg. EPSS 10.67% Exploit Prob.
Latest CVE CVE-2026-21637 Jan 20

Security Vulnerability Index

Page 17 / 70
7.5 CVSS

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

EPSS: 0.62%
10.0 CVSS

libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

EPSS: 1.59%
10.0 CVSS
CVE-2014-7192
RCE Exploit Found

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

EPSS: 42.57%
5.0 CVSS

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

EPSS: 0.69%
7.5 CVSS

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

EPSS: 4.84%
7.4 CVSS
CVE-2014-0224
Exploit Found

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

EPSS: 89.69%
7.5 CVSS
CVE-2013-6668
Exploit Found

Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

EPSS: 12.82%
7.5 CVSS

Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

EPSS: 1.54%