Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2018-11409EPSS 98%
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated b…
Splunk
after 7.0.1
HIGH 7.8
CVE-2018-0335
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to …
Prime Collaboration
Mitigation only
HIGH 7.5
CVE-2017-16225
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (…
Aegir
after 12.0.7
HIGH 7.5
CVE-2017-16202
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Cofeescript
Mitigation only
HIGH 7.5
CVE-2017-16203
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Coffescript
Mitigation only
HIGH 7.5
CVE-2017-16204
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Jquey
Mitigation only
HIGH 7.5
CVE-2017-16205
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Coffescript
Mitigation only
HIGH 7.5
CVE-2017-16206
The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Coffescript
Mitigation only
MEDIUM 5.3
CVE-2017-16126
The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is known to record and track user i…
Botbait
after 2.0.0
HIGH 7.5
CVE-2017-16074
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Crossenv
Mitigation only
HIGH 7.5
CVE-2017-16075
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Http Proxy.js
Mitigation only
HIGH 7.5
CVE-2017-16076
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Proxy.js
Mitigation only
HIGH 7.5
CVE-2017-16077
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Mongose
No fix yet
HIGH 7.5
CVE-2017-16078
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Shadowsock
Mitigation only
HIGH 7.5
CVE-2017-16079
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Smb
Mitigation only
HIGH 7.5
CVE-2017-16080
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Nodesass
Mitigation only
HIGH 7.5
CVE-2017-16081
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Cross Env.js
Mitigation only
HIGH 7.5
CVE-2017-16056
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Mssql.js
Mitigation only
HIGH 7.5
CVE-2017-16057
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Nodemssql
Mitigation only
HIGH 7.5
CVE-2017-16058
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Gruntcli
Mitigation only
HIGH 7.5
CVE-2017-16059
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Mssql Node
Mitigation only
HIGH 7.5
CVE-2017-16060
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Babelcli
Mitigation only
HIGH 7.5
CVE-2017-16063
node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Node Opensl
Mitigation only
HIGH 7.5
CVE-2017-16064
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Node Openssl
Mitigation only
HIGH 7.5
CVE-2017-16065
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Openssl.js
Mitigation only
HIGH 7.5
CVE-2017-16066
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Opencv.js
Mitigation only
HIGH 7.5
CVE-2017-16067
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Node Opencv
Mitigation only
HIGH 7.5
CVE-2017-16068
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Ffmepg
Mitigation only
HIGH 7.5
CVE-2017-16069
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Nodeffmpeg
Mitigation only
HIGH 7.5
CVE-2017-16070
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Nodecaffe
Mitigation only