Harborist

First CVE: Jun 23, 2025Active for: 1 year
12
CVEs Published
More CVEs Published than 30% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 62% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Harborist over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 23, 2025
12 months ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs

All CVEs published by Harborist as a CNA, regardless of affected vendor or product.

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character usi
May 22, 20268.138NONO
shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every i
Jun 25, 20267.536NONO
form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concate
Jun 12, 20267.536NONO
Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.
Aug 20, 20259.133NONO
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.
Aug 20, 20259.131NONO
Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This is
Jul 18, 20259.431NONO
### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is syn
May 17, 20265.327NONO
### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory
Feb 12, 20267.527NONO
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.
Jun 23, 20259.127NONO
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issu
Jun 23, 20259.127NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA12 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (66.7%)
High4 (33.3%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Harborist as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Harborist as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs