CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-11188

    Last Modified: 21 Nov 2024

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 46 of 46).

    Published: 1 Jun 2018
    8.8
    High

    CVE-2018-11189

    Last Modified: 21 Nov 2024

    Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 1 of 6).

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-11522

    Last Modified: 21 Nov 2024

    Yosoro 1.0.4 has stored XSS.

    Published: 1 Jun 2018
    4.8
    Medium

    CVE-2018-11564

    Last Modified: 21 Nov 2024

    Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2018-3756

    Last Modified: 21 Nov 2024

    Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a single node to sign a transaction and/or block multiple times, each with a random nonce, and have other validating nodes accept them as separate valid signatures.

    Published: 1 Jun 2018
    9.8
    Critical

    CVE-2018-3757

    Last Modified: 21 Nov 2024

    Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.

    Published: 1 Jun 2018
    5.3
    Medium

    CVE-2018-3809

    Last Modified: 21 Nov 2024

    Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.

    Published: 1 Jun 2018
    6.8
    Medium

    CVE-2018-11195

    Last Modified: 21 Nov 2024

    Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to their Mahara credentials.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2018-11196

    Last Modified: 21 Nov 2024

    Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. In contrast to other ZIP files that are uploaded, ClamAV (when activated) does not check Leap2A archives for viruses, allowing malicious files to be available for download. While files cannot be executed on Mahara itself, Mahara can be used to transfer such files to user computers.

    Published: 1 Jun 2018
    8.8
    High

    CVE-2018-11538

    Last Modified: 21 Nov 2024

    servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10576

    Last Modified: 21 Nov 2024

    Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10581

    Last Modified: 21 Nov 2024

    Steroids is PhoneGap on Steroids, providing native UI elements, multiple WebViews and enhancements for better developer productivity. steroids downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested tarball with an attacker controlled tarball if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10592

    Last Modified: 21 Nov 2024

    jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10605

    Last Modified: 21 Nov 2024

    dalek-browser-ie is Internet Explorer bindings for DalekJS. dalek-browser-ie downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10618

    Last Modified: 21 Nov 2024

    node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10631

    Last Modified: 21 Nov 2024

    jvminstall is a module for downloading and unpacking jvm to local system. jvminstall downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10579

    Last Modified: 21 Nov 2024

    Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10582

    Last Modified: 21 Nov 2024

    closurecompiler is a Closure Compiler for node.js. closurecompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10587

    Last Modified: 21 Nov 2024

    wasdk is a toolkit for creating WebAssembly modules. wasdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10588

    Last Modified: 21 Nov 2024

    nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10594

    Last Modified: 21 Nov 2024

    ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10595

    Last Modified: 21 Nov 2024

    jdf-sass is a fork from node-sass, jdf use only. jdf-sass downloads executable resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested file with an attacker controlled file if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10599

    Last Modified: 21 Nov 2024

    sauce-connect is a Node.js wrapper over the SauceLabs SauceConnect.jar program for establishing a secure tunnel for intranet testing. sauce-connect downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10600

    Last Modified: 21 Nov 2024

    webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10606

    Last Modified: 21 Nov 2024

    grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10610

    Last Modified: 21 Nov 2024

    unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10612

    Last Modified: 21 Nov 2024

    dalek-browser-ie-canary is Internet Explorer bindings for DalekJS. dalek-browser-ie-canary downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10620

    Last Modified: 21 Nov 2024

    atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10625

    Last Modified: 21 Nov 2024

    headless-browser-lite is a minimal npm installer for phantomjs and slimerjs with no external dependencies. headless-browser-lite downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10626

    Last Modified: 21 Nov 2024

    mystem3 is a NodeJS wrapper for the Yandex MyStem 3. mystem3 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10632

    Last Modified: 21 Nov 2024

    apk-parser2 is a module which extracts Android Manifest info from an APK file. apk-parser2 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    5.9
    Medium

    CVE-2016-10630

    Last Modified: 21 Nov 2024

    install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10574

    Last Modified: 21 Nov 2024

    apk-parser3 is a module to extract Android Manifest info from an APK file. apk-parser3 versions before 0.1.3 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10575

    Last Modified: 21 Nov 2024

    Kindlegen is a simple Node.js wrapper of the official kindlegen program. Kindlegen versions before 1.1.0 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10580

    Last Modified: 21 Nov 2024

    nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10583

    Last Modified: 21 Nov 2024

    closure-utils is Utilities for Closure Library based projects. closure-utils downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10585

    Last Modified: 21 Nov 2024

    libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10619

    Last Modified: 21 Nov 2024

    pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10596

    Last Modified: 21 Nov 2024

    imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested tarball with an attacker controlled tarball if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    5.9
    Medium

    CVE-2016-10597

    Last Modified: 21 Nov 2024

    cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2016-10598

    Last Modified: 21 Nov 2024

    arrayfire-js is a module for ArrayFire for the Node.js platform. arrayfire-js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10602

    Last Modified: 21 Nov 2024

    haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10603

    Last Modified: 21 Nov 2024

    air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10604

    Last Modified: 21 Nov 2024

    dalek-browser-chrome is Google Chrome bindings for DalekJS. dalek-browser-chrome downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10607

    Last Modified: 21 Nov 2024

    openframe-glsviewer is a Openframe extension which adds support for shaders via glslViewer. openframe-glsviewer downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2016-10608

    Last Modified: 21 Nov 2024

    robot-js is a module for native system automation for node.js. robot-js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10609

    Last Modified: 21 Nov 2024

    chromedriver126 is chromedriver version 1.26 for linux OS. chromedriver126 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    5.9
    Medium

    CVE-2016-10613

    Last Modified: 21 Nov 2024

    bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10614

    Last Modified: 21 Nov 2024

    httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10615

    Last Modified: 21 Nov 2024

    curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018