16,510 vulnerabilities published in 2018
The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is kno
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o fo
dasafio is a web server. dasafio is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the f
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a know
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allo
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. Thi
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin
When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the
An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leaka
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is starte
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not
Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attac
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the add
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected,
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against
If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that other
On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will ha
WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security che
A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake ad
The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or a
The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NI
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of a
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The r
A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_expose
The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or
Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-
SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerabili
Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-doma
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" e
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a
The printing process can bypass local access protections to read files available through symlinks, bypassing local file
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still
If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rend
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible throug
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to sc
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta
The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin cont
Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When use
A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Cust
Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise p
If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission not
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started