Vulnerabilities > Sequelizejs > Sequelize > 1.3.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-22 | CVE-2023-25813 | SQL Injection vulnerability in Sequelizejs Sequelize Sequelize is a Node.js ORM tool. | 9.8 |
2023-02-16 | CVE-2023-22578 | Unspecified vulnerability in Sequelizejs Sequelize Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections. | 9.8 |
2023-02-16 | CVE-2023-22579 | Type Confusion vulnerability in Sequelizejs Sequelize Due to improper parameter filtering in the sequalize js library, can a attacker peform injection. | 8.8 |
2023-02-16 | CVE-2023-22580 | Information Exposure vulnerability in Sequelizejs Sequelize Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure. | 7.5 |
2019-10-29 | CVE-2019-10749 | SQL Injection vulnerability in Sequelizejs Sequelize sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect. | 9.8 |
2018-05-31 | CVE-2016-10554 | SQL Injection vulnerability in Sequelizejs Sequelize sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. | 9.8 |
2018-05-31 | CVE-2016-10553 | SQL Injection vulnerability in Sequelizejs Sequelize sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. | 9.8 |
2018-05-31 | CVE-2016-10550 | SQL Injection vulnerability in Sequelizejs Sequelize sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in their own SQL statements. | 9.8 |
2018-05-29 | CVE-2016-10556 | SQL Injection vulnerability in Sequelizejs Sequelize sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS In Postgres, SQLite, and Microsoft SQL Server there is an issue where arrays are treated as strings and improperly escaped. | 7.5 |