Whereis Project maintains a focused command-line utility used for file location and system discovery on Unix-like systems, with its vulnerability exposure centered on the whereis tool itself. The durable signal reflects input-handling weaknesses characteristic of system utilities that parse user-supplied arguments and shell commands, specifically improper input validation and command-injection vulnerabilities. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whereis Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3772CRITICAL Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary commands. The `whereis` module is deprecated and it is recommended | Jul 30, 2018 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whereis Project.
Media articles that mention a CVE ID that affects a product developed by Whereis Project — matched by CVE ID, not by vendor name.