CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
Prototype Pollution in robinbuschmann/sequelize-typescript
SQL Injection via replacements in sequelize
Sequalize - Unsafe fall-through in getWhereConditions
Sequalize - Default support for “raw attributes” when using parentheses
Sequalize - Bad query filtering leading to SQL errors
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/Maria…
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly…
Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for…
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for…
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for…
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for…
Showing 1 to 14 CVEs · page 1