Skip to main content

CWE archive

CWE-1333 CVEs

Programmatic archive

468 CVEs tagged with CWE-13335 Critical, 222 High, 202 Medium, 37 Low, 2 Unrated.

CVE-2022-24373

Published Sep 30, 2022

The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of C…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21222

Published Sep 30, 2022

The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.j…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37259

Published Sep 20, 2022

A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37260

Published Sep 15, 2022

A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37262

Published Sep 15, 2022

A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40023

Published Sep 7, 2022

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36064

Published Sep 6, 2022

Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to escape arguments for the Unix shel…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29158

Published Sep 2, 2022

Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25887

Published Aug 30, 2022

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment r…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36034

Published Aug 29, 2022

nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been patched in all versions above…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43309

Published Aug 24, 2022

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input to the "URI.e…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1930

Published Aug 22, 2022

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_stru…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35923

Published Aug 2, 2022

v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25858

Published Jul 15, 2022

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31147

Published Jul 14, 2022

The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31781

Published Jul 13, 2022

Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25758

Published Jul 1, 2022

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1954

Published Jul 1, 2022

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31110

Published Jun 29, 2022

RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to the `filter` and `filterout` parameters can cause an abnor…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40900

Published Jun 27, 2022

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 468 CVEsPage 16 of 19