CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2017-0938 HIGH

Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.

CVSS 7.5 EPSS 20.97% Feb 12, 2019
CVE-2018-16493 HIGH

A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending sla…

CVSS 7.5 EPSS 1.76% Feb 1, 2019
npm
CVE-2018-16492 CRITICAL

nodejs-extend: Prototype pollution can allow attackers to modify object properties

CVSS 9.8 EPSS 3.05% Feb 1, 2019
npm
CVE-2018-16491 CRITICAL

nodejs-extend: Prototype pollution in Object.prototype

CVSS 9.8 EPSS 1.72% Feb 1, 2019
npm
CVE-2018-16490 HIGH

nodejs-mpath: prototype pollution in Object.prototype

CVSS 7.5 EPSS 1.10% Feb 1, 2019
npm
CVE-2018-16489 CRITICAL

A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.

CVSS 9.8 EPSS 1.84% Feb 1, 2019
npm
CVE-2018-16487 MEDIUM

lodash: Prototype pollution in utilities function

CVSS 5.6 EPSS 1.55% Feb 1, 2019
RubyGemsnpm
CVE-2018-16486 CRITICAL

A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.

CVSS 9.8 EPSS 1.48% Feb 1, 2019
npm
CVE-2018-16485 MEDIUM

Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd…

CVSS 6.5 EPSS 1.33% Feb 1, 2019
npm
CVE-2018-16484 MEDIUM

A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special c…

CVSS 5.4 EPSS 0.61% Feb 1, 2019
npm
CVE-2018-16483 HIGH

A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.

CVSS 8.8 EPSS 1.16% Feb 1, 2019
npm
CVE-2018-16482 HIGH

A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file sy…

CVSS 7.5 EPSS 1.82% Feb 1, 2019
npm
CVE-2018-16481 MEDIUM

A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitizatio…

CVSS 6.1 EPSS 0.69% Feb 1, 2019
npm
CVE-2018-16480 MEDIUM

A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanitization of the fi…

CVSS 6.1 EPSS 0.77% Feb 1, 2019
npm
CVE-2018-16479 HIGH

Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes after the URL.

CVSS 7.5 EPSS 1.65% Feb 1, 2019
npm
CVE-2018-16469 HIGH

The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be p…

CVSS 7.5 EPSS 1.68% Oct 30, 2018
npm
CVE-2018-3787 HIGH

Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.

CVSS 7.5 EPSS 2.04% Aug 31, 2018
npm
CVE-2018-3776 MEDIUM

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

CVSS 5.3 EPSS 1.26% Aug 12, 2018
CVE-2018-3775 HIGH

Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authenticatio…

CVSS 8.8 EPSS 1.23% Aug 12, 2018
CVE-2018-3774 CRITICAL

nodejs-url-parse: incorrect hostname in url parsing

CVSS 9.8 EPSS 3.81% Aug 12, 2018
npm
CVE-2018-3779 CRITICAL

active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker cou…

CVSS 9.8 EPSS 6.13% Aug 10, 2018
CVE-2018-3778 MEDIUM

Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.

CVSS 5.3 EPSS 1.42% Aug 8, 2018
npm
CVE-2018-3771 MEDIUM

An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.

CVSS 6.1 EPSS 0.93% Jul 20, 2018
npm
CVE-2018-3770 MEDIUM

A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.

CVSS 5.5 EPSS 0.50% Jul 20, 2018
npm
CVE-2018-3760 HIGH

rubygem-sprockets: Path traversal in forbidden_request?() can allow remote attackers to read arbitrary files

CVSS 7.5 EPSS 26.72% Jun 26, 2018

Showing 1 to 25 CVEs · page 1 (more available)