Vulnerabilities (CVE)

Total 298628 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-3743 1 Hekto Project 1 Hekto 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
CVE-2018-3741 1 Rubyonrails 1 Html Sanitizer 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.
CVE-2018-3740 1 Sanitize Project 1 Sanitize 2024-11-21 5.0 MEDIUM 7.5 HIGH
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
CVE-2018-3739 1 Https-proxy-agent Project 1 Https-proxy-agent 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).
CVE-2018-3738 1 Protobufjs Project 1 Protobufjs 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
CVE-2018-3737 1 Joyent 1 Sshpk 2024-11-21 5.0 MEDIUM 7.5 HIGH
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
CVE-2018-3735 1 Bracket-template Project 1 Bracket-template 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
CVE-2018-3734 1 Stattic Project 1 Stattic 2024-11-21 5.0 MEDIUM 7.5 HIGH
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path.
CVE-2018-3733 1 Crud-file-server Project 1 Crud-file-server 2024-11-21 5.0 MEDIUM 7.5 HIGH
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
CVE-2018-3732 1 Resolve-path Project 1 Resolve-path 2024-11-21 5.0 MEDIUM 7.5 HIGH
resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths with certain special characters, which allows a malicious user to read content of any file with known path.
CVE-2018-3731 1 Public.js Project 1 Public.js 2024-11-21 5.0 MEDIUM 7.5 HIGH
public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
CVE-2018-3730 1 Mcstatic Project 1 Mcstatic 2024-11-21 5.0 MEDIUM 7.5 HIGH
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
CVE-2018-3729 1 Localhost-now Project 1 Localhost-now 2024-11-21 5.0 MEDIUM 7.5 HIGH
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CVE-2018-3728 1 Hapijs 1 Hoek 2024-11-21 6.5 MEDIUM 8.8 HIGH
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
CVE-2018-3727 1 626 Project 1 626 2024-11-21 5.0 MEDIUM 7.5 HIGH
626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CVE-2018-3726 1 Crud-file-server Project 1 Crud-file-server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CVE-2018-3725 1 Hekto Project 1 Hekto 2024-11-21 5.0 MEDIUM 7.5 HIGH
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CVE-2018-3724 1 General-file-server Project 1 General-file-server 2024-11-21 5.0 MEDIUM 7.5 HIGH
general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path.
CVE-2018-3723 1 Defaults-deep Project 1 Defaults-deep 2024-11-21 6.5 MEDIUM 8.8 HIGH
defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
CVE-2018-3722 1 Merge-deep Project 1 Merge-deep 2024-11-21 6.5 MEDIUM 8.8 HIGH
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.