DntCVEs & Vulnerabilities
2 CVEs affecting Dnt products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
im-metadata 1im-resize 1
CVE-2019-10788CRITICAL
im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.
5 Feb 2020
9.8
CVSS
CVE-2019-10787CRITICAL
im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.
5 Feb 2020
9.8
CVSS
← PrevPage 1 / 1Next →