VDB
CVE-2024-42640
CVE-2024-42640
PUBLISHED
KEV
CVSS 10 CRITICAL
angular-base64-upload vulnerable to unauthenticated remote code execution
EPSS 45.10% · 98.7th percentile
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
45.10%
98.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| npm | angular-base64-upload | 0, 0, 0 |
| n/a | n/a | n/a, n/a |
| angular-base64-upload-project | angular-base64-upload | 0, 0 |
Timeline
- Oct 11, 2024 CVE Published
- Oct 11, 2024 PoC Published
- Oct 12, 2024 EPSS Score
- Oct 13, 2024 PoC Published
- Oct 13, 2024 PoC Published
- Oct 13, 2024 PoC Published
- Oct 14, 2024 VulnCheck KEV Exploitation
- Oct 14, 2024 Coalition ESS Score
- Oct 14, 2024 PoC Published
- Oct 15, 2024 VulnCheck KEV Exploitation
- Oct 15, 2024 PoC Published
- Oct 16, 2024 Coalition ESS Score