Vulnerabilities > NIM Lang > NIM

DATE CVE VULNERABILITY TITLE RISK
2023-01-13 CVE-2021-46872 Cross-site Scripting vulnerability in Nim-Lang NIM and Nimforum
An issue was discovered in Nim before 1.6.2.
network
low complexity
nim-lang CWE-79
6.1
2021-05-07 CVE-2021-29495 Improper Certificate Validation vulnerability in Nim-Lang NIM
Nim is a statically typed compiled systems programming language.
network
low complexity
nim-lang CWE-295
5.0
2021-03-26 CVE-2021-21374 Improper Certificate Validation vulnerability in Nim-Lang NIM
Nimble is a package manager for the Nim programming language.
network
nim-lang CWE-295
6.8
2021-03-26 CVE-2021-21373 Improper Certificate Validation vulnerability in Nim-Lang NIM
Nimble is a package manager for the Nim programming language.
network
nim-lang CWE-295
4.3
2021-03-26 CVE-2021-21372 OS Command Injection vulnerability in Nim-Lang NIM
Nimble is a package manager for the Nim programming language.
network
low complexity
nim-lang CWE-78
8.8
2021-01-30 CVE-2020-15690 Injection vulnerability in Nim-Lang NIM 1.2/1.2.2/1.2.4
In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.
network
low complexity
nim-lang CWE-74
7.5
2020-08-14 CVE-2020-15694 Improper Input Validation vulnerability in Nim-Lang NIM 1.2/1.2.2/1.2.4
In Nim 1.2.4, the standard library httpClient fails to properly validate the server response.
network
low complexity
nim-lang CWE-20
5.0
2020-08-14 CVE-2020-15693 Injection vulnerability in Nim-Lang NIM 1.2/1.2.2/1.2.4
In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL.
network
low complexity
nim-lang CWE-74
6.4
2020-08-14 CVE-2020-15692 Argument Injection or Modification vulnerability in Nim-Lang NIM 1.2/1.2.2/1.2.4
In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser.
network
low complexity
nim-lang CWE-88
critical
10.0