CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-30951 HIGH

Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type

CVSS 7.5 EPSS 0.48% Mar 10, 2026
npm
CVE-2023-6293 HIGH

Prototype Pollution in robinbuschmann/sequelize-typescript

CVSS 7.1 EPSS 0.59% Nov 24, 2023
npm
CVE-2023-25813 CRITICAL

SQL Injection via replacements in sequelize

CVSS 10.0 EPSS 1.44% Feb 22, 2023
npm
CVE-2023-22579 CRITICAL

Sequalize - Unsafe fall-through in getWhereConditions

CVSS 9.9 EPSS 0.81% Feb 16, 2023
npm
CVE-2023-22578 CRITICAL

Sequalize - Default support for “raw attributes” when using parentheses

CVSS 10.0 EPSS 0.83% Feb 16, 2023
npm
CVE-2023-22580 HIGH

Sequalize - Bad query filtering leading to SQL errors

CVSS 7.5 EPSS 0.58% Feb 16, 2023
npm
CVE-2019-10749 CRITICAL

sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.

CVSS 9.8 EPSS 1.23% Oct 29, 2019
npm
CVE-2019-10748 CRITICAL

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/Maria…

CVSS 9.8 EPSS 1.31% Oct 28, 2019
npm
CVE-2019-10752 CRITICAL

Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly…

CVSS 9.8 EPSS 1.46% Oct 17, 2019
npm
CVE-2019-11069 HIGH

Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.

CVSS 7.5 EPSS 1.82% Apr 10, 2019
npm
CVE-2016-10554 CRITICAL

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for…

CVSS 9.8 EPSS 1.91% May 31, 2018
npm
CVE-2016-10553 CRITICAL

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for…

CVSS 9.8 EPSS 1.29% May 31, 2018
npm
CVE-2016-10550 CRITICAL

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for…

CVSS 9.8 EPSS 1.91% May 31, 2018
npm
CVE-2016-10556 HIGH

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for…

CVSS 7.5 EPSS 1.34% May 29, 2018
npm

Showing 1 to 14 CVEs · page 1