Export limit exceeded: 24494 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403775 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (1 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107703 | 1 Enmaso | 1 Node-convert | 2026-10-09 | 9.8 Critical |
| @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges. | ||||
Page 1 of 1.
