Unknown · CVSS Not scored
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter.
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
byucslabsix is an http server. byucslabsix is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
static-html-server is a static file server. static-html-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
High · CVSS 7.5
An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.
Published Jun 1, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
jansenstuffpleasework is a file server. jansenstuffpleasework is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
Published Jun 13, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
getcityapi.yoehoehne is a web server. getcityapi.yoehoehne is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma_radio_chan_stats_event_handler() for the derived length len leading to a subsequent buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
uv-tj-demo is a static file server. uv-tj-demo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()).
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
cypserver is a static file server. cypserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or not. To do this, uri-js uses a regular expression, This regular expression is vulnerable to redos. This causes the program to hang and the CPU to idle at 100% usage while uri-js is trying to validate if the supplied URL is valid or not. To check if you're vulnerable, look for a call to `require("uri-js").parse()` where a user is able to send their own input. This affects uri-js 2.1.1 and earlier.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user interface.
Published Jun 22, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rsp_per_ndi_list" is very large which can then lead to a heap overwrite of the heap object end_rsp in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted currency decimal-sign data.
Published Jun 14, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter.
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.
Published Jun 6, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.
Published Jun 6, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected.
Published Jun 23, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
ewgaddis.lab6 is a file server. ewgaddis.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.
Published Jun 7, 2018 · Updated Sep 17, 2024