Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Splunk MEDIUM 5.3
CVE-2018-11409EPSS 98%

Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated b…

Fix: after 7.0.1
Fix from $1,600 2018-06-08
Prime Collaboration HIGH 7.8
CVE-2018-0335

A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to …

Mitigation only
Fix from $1,950 2018-06-07
Aegir HIGH 7.5
CVE-2017-16225

aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (…

Fix: after 12.0.7
Fix from $1,950 2018-06-07
Cofeescript HIGH 7.5
CVE-2017-16202

The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Mitigation only
Fix from $1,950 2018-06-07
Coffescript HIGH 7.5
CVE-2017-16203

The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Mitigation only
Fix from $1,950 2018-06-07
Jquey HIGH 7.5
CVE-2017-16204

The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Mitigation only
Fix from $1,950 2018-06-07
Coffescript HIGH 7.5
CVE-2017-16205

The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Mitigation only
Fix from $1,950 2018-06-07
Coffescript HIGH 7.5
CVE-2017-16206

The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Mitigation only
Fix from $1,950 2018-06-07
Botbait MEDIUM 5.3
CVE-2017-16126

The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is known to record and track user i…

Fix: after 2.0.0
Fix from $1,600 2018-06-07
Crossenv HIGH 7.5
CVE-2017-16074

crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Http Proxy.js HIGH 7.5
CVE-2017-16075

http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Proxy.js HIGH 7.5
CVE-2017-16076

proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Mongose HIGH 7.5
CVE-2017-16077

mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

No fix yet
Fix from $1,950 2018-06-07
Shadowsock HIGH 7.5
CVE-2017-16078

shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Smb HIGH 7.5
CVE-2017-16079

smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Nodesass HIGH 7.5
CVE-2017-16080

nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Cross Env.js HIGH 7.5
CVE-2017-16081

cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Mssql.js HIGH 7.5
CVE-2017-16056

mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Nodemssql HIGH 7.5
CVE-2017-16057

nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Gruntcli HIGH 7.5
CVE-2017-16058

gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Mssql Node HIGH 7.5
CVE-2017-16059

mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Babelcli HIGH 7.5
CVE-2017-16060

babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Node Opensl HIGH 7.5
CVE-2017-16063

node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Node Openssl HIGH 7.5
CVE-2017-16064

node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Openssl.js HIGH 7.5
CVE-2017-16065

openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Opencv.js HIGH 7.5
CVE-2017-16066

opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Node Opencv HIGH 7.5
CVE-2017-16067

node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Ffmepg HIGH 7.5
CVE-2017-16068

ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Nodeffmpeg HIGH 7.5
CVE-2017-16069

nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Nodecaffe HIGH 7.5
CVE-2017-16070

nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07