k
kindspells
Security Risk Profile
31
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 2 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 28, 2024 to present
2
Total CVEs
2
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
31/100
low
Severity Distribution
Critical
0High
2Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
No CWE data available
Most Affected Products
1. npm/@kindspells/astro-shield2
2. kindspells Astro-Shield2
3. IBM Cognos Analytics2
Recent Vulnerabilities
See more →CVE-2024-30250
CVSS 7.5EPSS 0%high
In Astro-Shield, setting a correct `integrity` attribute to injected code allows to bypass the allow-lists
Apr 1, 2024
CVE-2024-29896
CVSS 7.5EPSS 0%high
Astro-Shield's Content-Security-Policy header generation in middleware could be compromised by malicious injections
Mar 28, 2024
Monitor kindspells in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.