|
223001
|
8.1 |
HIGH
Network
|
npmjs opensuse oracle fedoraproject redhat
|
npm leap graalvm fedora enterprise_linux enterprise_linux_eus
|
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly …
|
CWE-22
Path Traversal
|
CVE-2019-16776
|
2024-11-21 13:31 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223002
|
6.5 |
MEDIUM
Network
|
redhat npmjs opensuse oracle fedoraproject
|
enterprise_linux enterprise_linux_eus npm leap graalvm fedora
|
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon…
|
-
|
CVE-2019-16775
|
2024-11-21 13:31 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223003
|
7.5 |
HIGH
Network
|
microfocus
|
acutoweb
|
Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and download files from the filesystem of the system runn…
|
NVD-CWE-noinfo
|
CVE-2019-17087
|
2024-11-21 13:31 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223004
|
6.1 |
MEDIUM
Network
|
serialize-to-js_project
|
serialize-to-js
|
The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulne…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16772
|
2024-11-21 13:31 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223005
|
6.5 |
MEDIUM
Network
|
linecorp
|
armeria
|
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized d…
|
CWE-74
Injection
|
CVE-2019-16771
|
2024-11-21 13:31 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223006
|
7.5 |
HIGH
Network
|
puma debian
|
puma debian_linux
|
In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Pum…
|
-
|
CVE-2019-16770
|
2024-11-21 13:31 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223007
|
4.3 |
MEDIUM
Network
|
sylius
|
sylius
|
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and prop…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-16768
|
2024-11-21 13:31 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223008
|
5.4 |
MEDIUM
Network
|
verizon
|
serialize-javascript
|
The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This …
|
CWE-79
Cross-site Scripting
|
CVE-2019-16769
|
2024-11-21 13:31 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223009
|
7.5 |
HIGH
Network
|
pivx decentralized_anonymous_payment_system_project
|
private_instant_verified_transactions decentralized_anonymous_payment_system
|
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their b…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2019-16753
|
2024-11-21 13:31 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223010
|
4.3 |
MEDIUM
Network
|
pivx dash officialdapscoin
|
private_instant_verified_transactions dash_core decentralized_anonymous_payment_system
|
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network an…
|
CWE-352
Origin Validation Error
|
CVE-2019-16752
|
2024-11-21 13:31 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|