Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,299 of 16,510 · Page 100/126
5.3
CVE-2017-16126

The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is kno

5.3
CVE-2017-16137

The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o fo

5.3
CVE-2017-16179

dasafio is a web server. dasafio is vulnerable to a directory traversal issue, giving an attacker access to the filesyst

5.3
CVE-2017-16222

elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the f

5.3
CVE-2018-3718

serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is

5.3
CVE-2018-0329

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area

5.3
CVE-2018-11409

Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json

5.3
CVE-2016-9071

Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a know

5.3
CVE-2017-5383

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allo

5.3
CVE-2017-5405

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. Thi

5.3
CVE-2017-5408

Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o

5.3
CVE-2017-5415

An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin

5.3
CVE-2017-5417

When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the

5.3
CVE-2017-5418

An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leaka

5.3
CVE-2017-5426

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is starte

5.3
CVE-2017-5462

A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not

5.3
CVE-2017-5463

Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attac

5.3
CVE-2017-7763

Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this

5.3
CVE-2017-7764

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the add

5.3
CVE-2017-7782

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected,

5.3
CVE-2017-7789

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid

5.3
CVE-2017-7791

On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary

5.3
CVE-2017-7808

A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against

5.3
CVE-2017-7812

If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that other

5.3
CVE-2017-7815

On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will ha

5.3
CVE-2017-7816

WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security che

5.3
CVE-2017-7817

A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake ad

5.3
CVE-2017-7820

The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or a

5.3
CVE-2017-7822

The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NI

5.3
CVE-2017-7825

Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of a

5.3
CVE-2017-7829

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The r

5.3
CVE-2017-7831

A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_expose

5.3
CVE-2017-7832

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or

5.3
CVE-2017-7833

Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-

5.3
CVE-2017-7837

SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerabili

5.3
CVE-2017-7838

Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-doma

5.3
CVE-2017-7842

If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" e

5.3
CVE-2017-7848

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects

5.3
CVE-2018-5106

Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a

5.3
CVE-2018-5107

The printing process can bypass local access protections to read files available through symlinks, bypassing local file

5.3
CVE-2018-5109

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still

5.3
CVE-2018-5110

If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rend

5.3
CVE-2018-5114

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible throug

5.3
CVE-2018-5117

If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to sc

5.3
CVE-2018-5118

The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta

5.3
CVE-2018-5119

The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin cont

5.3
CVE-2018-5121

Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When use

5.3
CVE-2018-5138

A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Cust

5.3
CVE-2018-5140

Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise p

5.3
CVE-2018-5142

If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission not

Scan for 2018 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started