Better streaming static file server with Range and conditional-GET support
81%
Total Score
62
95
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10253 send is vulnerable to Cross-site Scripting (XSS) in versions 0.9.0 - 0.18.0 and 1.0.0 - 1.0.0. | 0.9.0 - 0.18.01.0.0 - 1.0.0 | Medium |
CVE-2015-8859 send is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 0.11.1. | 0.0.0 - 0.11.1 | Medium |
CVE-2014-6394 send is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 0.8.4. | 0.0.0 - 0.8.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
ms Version ^2.1.3 | — | — |
etag Version ^1.8.1 | — | — |
debug Version ^4.4.3 | — | — |
fresh Version ^2.0.0 | — | — |
statuses Version ^2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant