|
266421
|
9.8 |
CRITICAL
Network
|
sequelizejs
|
sequelize
|
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, se…
|
CWE-89
SQL Injection
|
CVE-2016-10554
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266422
|
9.8 |
CRITICAL
Network
|
sequelizejs
|
sequelize
|
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed…
|
CWE-89
SQL Injection
|
CVE-2016-10553
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266423
|
7.4 |
HIGH
Network
|
infragistics
|
igniteui
|
igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.
|
CWE-254
7PK - Security Features
|
CVE-2016-10552
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266424
|
9.8 |
CRITICAL
Network
|
sequelizejs
|
sequelize
|
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `lim…
|
CWE-89
SQL Injection
|
CVE-2016-10550
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266425
|
4.4 |
MEDIUM
Network
|
sailsjs
|
sails
|
Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration where the value of the origin header is reflected as the val…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10549
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266426
|
6.1 |
MEDIUM
Network
|
reduce-css-calc_project
|
reduce-css-calc
|
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10548
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266427
|
6.1 |
MEDIUM
Network
|
mozilla
|
nunjucks
|
Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10547
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266428
|
9.8 |
CRITICAL
Network
|
pouchdb
|
pouchdb
|
An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch i…
|
CWE-94
Code Injection
|
CVE-2016-10546
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266429
|
5.9 |
MEDIUM
Network
|
uws_project
|
uws
|
uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibility used compression will shrink said 256mb down t…
|
CWE-20
Improper Input Validation
|
CVE-2016-10544
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266430
|
5.3 |
MEDIUM
Network
|
call_project
|
call
|
call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty parameters, which could result in invalid input bypas…
|
CWE-20
Improper Input Validation
|
CVE-2016-10543
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|