Vulnerabilities (CVE)

Filtered by vendor Pdf-image Project Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8132 1 Pdf-image Project 1 Pdf-image 2024-11-21 7.5 HIGH 9.8 CRITICAL
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
CVE-2018-3757 1 Pdf-image Project 1 Pdf-image 2024-11-21 10.0 HIGH 9.8 CRITICAL
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.