← All credits
Unknown
11 vulnerability records and advisories credit this contributor.
CVE-2025-11149
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.
CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
CVE-2022-25857
Denial of Service (DoS)
CVE-2022-25845
Deserialization of Untrusted Data
CVE-2022-23812
Malicious Package
CVE-2021-23567
Denial of Service (DoS)
CVE-2021-23495
Open Redirect
CVE-2021-23446
Regular Expression Denial of Service (ReDoS)
CVE-2021-23418
XML External Entity (XXE) Injection
CVE-2021-23330
Command Injection