Vulnerabilities > Blamer Project

DATE CVE VULNERABILITY TITLE RISK
2023-09-19 CVE-2023-26143 Argument Injection or Modification vulnerability in Blamer Project Blamer
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API.
network
low complexity
blamer-project CWE-88
critical
9.1
2020-03-20 CVE-2020-8137 Code Injection vulnerability in Blamer Project Blamer
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.
network
low complexity
blamer-project CWE-94
critical
9.8
2020-03-11 CVE-2019-10807 OS Command Injection vulnerability in Blamer Project Blamer
Blamer versions prior to 1.0.1 allows execution of arbitrary commands.
network
low complexity
blamer-project CWE-78
critical
9.8