Henrik Joreteg html-parse-stringify是 (Henrik Joreteg)开源的一个应用软件。提供了一种可以快速将HTML解析为AST并将其字符串化为原始字符串的方法。 html-parse-stringify before 2.0.1 存在安全漏洞,该漏洞源于发送某些输入可能会导致用于解析的某个正则表达式回溯、冻结进程。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | html-parse-stringify | unspecified ~ 2.0.1 | - |
|
| - | html-parse-stringify2 | 0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-23344 | 9.8 CRITICAL | Remote Code Execution (RCE) |
| CVE-2020-35328 | Courier Management System 跨站脚本漏洞 | |
| CVE-2020-35636 | CGAL 输入验证错误漏洞 | |
| CVE-2020-35628 | CGAL 输入验证错误漏洞 | |
| CVE-2020-28636 | CGAL 输入验证错误漏洞 | |
| CVE-2020-28601 | CGAL libcgal CGAL 安全漏洞 | |
| CVE-2019-18628 | Xerox AltaLink 安全漏洞 | |
| CVE-2019-18629 | Xerox AltaLink 安全漏洞 | |
| CVE-2020-24036 | Fork ForkCMS 安全漏洞 | |
| CVE-2020-24912 | Matthias Van Woensel qcubed 跨站脚本漏洞 | |
| CVE-2020-24913 | Matthias Van Woensel qcubed SQL注入漏洞 | |
| CVE-2020-24914 | Matthias Van Woensel qcubed 安全漏洞 | |
| CVE-2020-35327 | SourceCodester Courier Management System SQL注入漏洞 | |
| CVE-2021-27314 | Sourcecodesterk Doctor Appointment System SQL注入漏洞 | |
| CVE-2020-35329 | SourceCodester Courier Management System SQL注入漏洞 | |
| CVE-2021-27217 | yubihsm-shell 缓冲区错误漏洞 | |
| CVE-2020-8298 | fs-path 命令注入漏洞 | |
| CVE-2021-26293 | AfterLogic Aurora 路径遍历漏洞 | |
| CVE-2021-26988 | Netapp Clustered Data ONTAP 安全漏洞 | |
| CVE-2021-26989 | Netapp Clustered Data ONTAP 安全漏洞 |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet