Package Hub
Vendor:
First CVE: Mar 29, 2016 · Active for 10 years
39
Total CVEs
More Total CVEs than 97% of tracked products
9.8
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Package Hub over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 29, 2016
10 years ago
Most Recent CVE
Aug 19, 2020
2,166 days ago
CVE Severity & Scoring
Package Hub39 CVEs
41%
56%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (5.1%)
Network37 (94.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None10 (25.6%)
Unknown0 (0.0%)
Required29 (74.4%)
Privileges Required
Low6 (15.4%)
High0 (0.0%)
None33 (84.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1646HIGH The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows re | Mar 29, 2016 | 8.8 | 86 | YES | NO |
CVE-2019-11730MEDIUM A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are | Jul 23, 2019 | 6.5 | 32 | NO | NO |
CVE-2019-11709CRITICAL Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we pres | Jul 23, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-13764HIGH Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Dec 10, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-13734HIGH Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Dec 10, 2019 | 8.8 | 29 | NO | NO |
CVE-2020-10802HIGH In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain que | Mar 22, 2020 | 8.0 | 28 | NO | NO |
CVE-2019-19925HIGH zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. | Dec 24, 2019 | 7.5 | 28 | NO | NO |
CVE-2019-19923HIGH flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer | Dec 24, 2019 | 7.5 | 28 | NO | NO |
CVE-2020-10804HIGH In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and li | Mar 22, 2020 | 8.0 | 27 | NO | NO |
CVE-2020-6415HIGH Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Feb 11, 2020 | 8.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (39 CVEs).
CISA KEV
1 CVE
2.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (39 CVEs).
Media Mentions
Signals from CVEs in this product scope (39 CVEs).
Top CNAs Publishing CVEs For Package Hub
Top CWEs
Versions
No cataloged versions.