Unknown · CVSS Not scored
11xiaoli is a simple file server. 11xiaoli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Medium · CVSS 4.4
IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 127392.
Published Jun 8, 2018 · Updated Sep 16, 2024
High · CVSS 8.8
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
pytservce is a static file server. pytservce is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
cuciuci is a simple fileserver. cuciuci is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.
Published Jun 12, 2018 · Updated Sep 16, 2024
Low · CVSS 3.7
An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resulting in a new program being written to the memory module. An attacker can send an unauthenticated packet to trigger this vulnerability.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 16, 2024
High · CVSS 8.8
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
Published Jun 29, 2017 · Updated Sep 16, 2024
High · CVSS 8.8
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter.
Published Jun 23, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
dcserver is a static file server. dcserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. This is compounded by `f2e-server` requiring elevated privileges to run.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
open-device creates a web interface for any device. open-device is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may result in excessive CPU and/or memory consumption. An attacker might exploit such a weakness for a DoS attack. To exploit this the attacker must control the location (URL) that superagent makes a request to.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Published Jun 7, 2018 · Updated Sep 16, 2024
Medium · CVSS 6.8
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 135521.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.
Published Jun 7, 2018 · Updated Sep 16, 2024
High · CVSS 8.8
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
myserver.alexcthomas18 is a file server. myserver.alexcthomas18 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
Published Jun 8, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
unicorn-list is a web framework. unicorn-list is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
lab6drewfusbyu is an http server. lab6drewfusbyu is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) is used.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
myprolyz is a static file server. myprolyz is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
High · CVSS 7.5
An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.
Published Jun 1, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string "_pub.pem".
Published Jun 30, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120744.
Published Jun 28, 2017 · Updated Sep 16, 2024