Unknown · CVSS Not scored
enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
lab6.brit95 is a file server. lab6.brit95 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
sly07 is an API for censoring text. sly07 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
High · CVSS 7.5
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can cause a buffer overflow.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earlier causes a denial of service. When a crafted TCP packet is received, the device reboots immediately.
Published Jun 25, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
zwserver is a weather web server. zwserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\save-revision.php and core\admin\modules\pages\revisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users.
Published Jun 6, 2017 · Updated Sep 16, 2024
Medium · CVSS 5.9
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 128610.
Published Jun 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
utahcityfinder constructs lists of Utah cities with a certain prefix. utahcityfinder is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The module pandora-doomsday infects other modules. It's since been unpublished from the registry.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
susu-sum is a static file server. susu-sum is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name.
Published Jun 6, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which could lead to local escalation of privilege with no additional execution privileges needed. User interaction not needed for exploitation. This issue is rated as high. Version: N/A. Android: A-69559414. Reference: N-CVE-2017-6290.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
section2.madisonjbrooks12 is a simple web server. section2.madisonjbrooks12 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In SimpleCE 2.3.0, an authenticated XSS vulnerability was found on index.php/content/text/1?return_url=[XSS] exploitable as a regular or admin user.
Published Jun 15, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
censorify.tanisjr is a simple web server and API RESTful service. censorify.tanisjr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of service.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
whispercast is a file server. whispercast is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
caolilinode is a simple file server. caolilinode is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
serverzyy is a static file server. serverzyy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
dylmomo is a simple file server. dylmomo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter.
Published Jun 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted common data.
Published Jun 14, 2017 · Updated Sep 16, 2024
High · CVSS 8.8
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during the SMTP configuration tests resulting in command execution
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.
Published Jun 30, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
mockserve is a file server. mockserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024