16,510 vulnerabilities published in 2018
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished b
gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malici
An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connectio
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code t
SELA (aka SimplE Lossless Audio) v0.1.2-alpha has a stack-based buffer overflow in the core/apev2.c init_apev2_keys func
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string repr
Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacke
ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memo
A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a
jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in t
MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS
The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable unde
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Ko
Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handsh
An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek Neuro
An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks
An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek Neuro
ngiflib.c in MiniUPnP ngiflib 0.4 has an infinite loop in DecodeGifImg and LoadGif.
arrayfire-js is a module for ArrayFire for the Node.js platform. arrayfire-js downloads binary resources over HTTP, whic
robot-js is a module for native system automation for node.js. robot-js downloads binary resources over HTTP, which leav
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification by
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on ve
In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of
In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if us
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKit
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature s
hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding`
Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that force
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1
hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulner
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and ea
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by
`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
`hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started