|
251091
|
7.5 |
HIGH
Network
|
hapijs
|
hapi
|
hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to han…
|
CWE-20
Improper Input Validation
|
CVE-2017-16013
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251092
|
6.1 |
MEDIUM
Network
|
ag-grid
|
ag-grid
|
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16009
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251093
|
6.1 |
MEDIUM
Network
|
i18next
|
i18next
|
i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of th…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16008
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251094
|
5.9 |
MEDIUM
Network
|
cisco
|
node-jose
|
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an …
|
NVD-CWE-noinfo
|
CVE-2017-16007
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251095
|
6.1 |
MEDIUM
Network
|
remarkable_project
|
remarkable
|
Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute javascript.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16006
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251096
|
7.5 |
HIGH
Network
|
joyent
|
http-signature
|
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signatur…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2017-16005
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251097
|
7.5 |
HIGH
Network
|
gaoxuyan_project
|
gaoxuyan
|
gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
|
CWE-22
Path Traversal
|
CVE-2017-16153
|
2024-11-21 12:15 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251098
|
7.5 |
HIGH
Network
|
node-tkinter_project
|
node-tkinter
|
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16062
|
2024-11-21 12:15 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251099
|
7.5 |
HIGH
Network
|
tkinter_package
|
tkinter
|
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16061
|
2024-11-21 12:15 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251100
|
7.5 |
HIGH
Network
|
mysqljs_project
|
mysqljs
|
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16047
|
2024-11-21 12:15 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|