qs project
Security Risk Profile
38
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 5 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 1, 2017 to present
5
Total CVEs
4
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
38/100
low
Severity Distribution
Critical
0High
4Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Input Validation
3
Most Affected Products
1. Qs Project Qs30
2. npm/qs13
3. Qs Project Qs Node.js12
4. redhat/qs10
5. redhat/nodejs-qs5
Recent Vulnerabilities
See more →CVE-2026-2391
CVSS 6.3EPSS 0%medium
qs's arrayLimit bypass in comma parsing allows denial of service
2/12/2026
CVE-2025-15284
CVSS 8.7high
arrayLimit bypass in bracket notation allows DoS via memory exhaustion
12/29/2025
CVE-2022-24999
CVSS 7.5high
11/26/2022
CVE-2014-10064
CVSS 7.5high
5/31/2018🔧 No Patch
CVE-2017-1000048
CVSS 7.5high
3/1/2017
Monitor qs project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.