Total
298628 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-3743 | 1 Hekto Project | 1 Hekto | 2024-11-21 | 5.8 MEDIUM | 6.1 MEDIUM |
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server. | |||||
CVE-2018-3741 | 1 Rubyonrails | 1 Html Sanitizer | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately. | |||||
CVE-2018-3740 | 1 Sanitize Project | 1 Sanitize | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element. | |||||
CVE-2018-3739 | 1 Https-proxy-agent Project | 1 Https-proxy-agent | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON). | |||||
CVE-2018-3738 | 1 Protobufjs Project | 1 Protobufjs | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files. | |||||
CVE-2018-3737 | 1 Joyent | 1 Sshpk | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys. | |||||
CVE-2018-3735 | 1 Bracket-template Project | 1 Bracket-template | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template | |||||
CVE-2018-3734 | 1 Stattic Project | 1 Stattic | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3733 | 1 Crud-file-server Project | 1 Crud-file-server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3732 | 1 Resolve-path Project | 1 Resolve-path | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths with certain special characters, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3731 | 1 Public.js Project | 1 Public.js | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3730 | 1 Mcstatic Project | 1 Mcstatic | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3729 | 1 Localhost-now Project | 1 Localhost-now | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3728 | 1 Hapijs | 1 Hoek | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. | |||||
CVE-2018-3727 | 1 626 Project | 1 626 | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3726 | 1 Crud-file-server Project | 1 Crud-file-server | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. | |||||
CVE-2018-3725 | 1 Hekto Project | 1 Hekto | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3724 | 1 General-file-server Project | 1 General-file-server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3723 | 1 Defaults-deep Project | 1 Defaults-deep | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. | |||||
CVE-2018-3722 | 1 Merge-deep Project | 1 Merge-deep | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. |