Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2017-16119
Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service wh…
Fresh
0.5.2+
HIGH 7.5
CVE-2017-16086EPSS 9%
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given …
Ua Parser
Mitigation only
MEDIUM 6.5
CVE-2017-16021
uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or not. To do t…
Uri Js
after 2.1.1
HIGH 7.5
CVE-2017-16023
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to e…
Decamelize
Mitigation only
MEDIUM 5.9
CVE-2017-16025
Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerabili…
Nes
after 6.4.0
HIGH 7.5
CVE-2017-16030
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creat…
Useragent
after 2.1.12
HIGH 7.5
CVE-2017-16013
hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception…
Hapi
after 16.1.0
MEDIUM 5.3
CVE-2017-6153
Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly…
Big Ip Application Acceleration Manager
after 12.1.3
HIGH 7.5
CVE-2016-10539
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Lan…
Negotiator
after 0.6.0
HIGH 7.5
CVE-2016-10540
Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(…
Minimatch
after 3.0.1
HIGH 7.5
CVE-2016-10542EPSS 8%
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending…
Ws
after 1.1.0
MEDIUM 5.9
CVE-2016-10544
uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibil…
Uws
after 0.10.8
HIGH 7.5
CVE-2014-10064
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested obje…
Qs
1.0.0+
HIGH 7.5
CVE-2015-9239
ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
Ansi2html
No fix yet
HIGH 7.5
CVE-2016-10520
jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
Jadedown
after 0.0.3
HIGH 7.5
CVE-2016-10521
jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator.
Jshamcrest
after 0.7.1
HIGH 7.5
CVE-2016-10523
MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible with very li…
Mqtt Packet
3.4.6 / 4.0.5+
HIGH 8.2
CVE-2016-10524
i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is used for deve…
I18n Node Angular
1.4.0+
HIGH 7.5
CVE-2016-10527
The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.
Riot Compiler
Mitigation only
HIGH 7.5
CVE-2015-9241
Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a …
Hapi
11.1.3+
HIGH 7.5
CVE-2015-9242
Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads …
Ecstatic
1.4.0+
HIGH 7.5
CVE-2018-6237EPSS 6%
A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to s…
Smart Protection Server
No fix yet
MEDIUM 6.5
CVE-2016-8627
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via …
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2018-10827
LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/…
Litecart
2.1.2+
MEDIUM 6.5
CVE-2018-0285
A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interfac…
Prime Service Catalog
Mitigation only
MEDIUM 6.5
CVE-2018-1277
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may …
Garden Runc
1.13.0 / 1.28.0+
HIGH 7.5
CVE-2017-7651EPSS 5%
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. …
Debian Linux
after 1.4.14
HIGH 8.6
CVE-2018-0230
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Secu…
Secure Firewall Threat Defense
Mitigation only
HIGH 8.6
CVE-2018-0233
A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could al…
Secure Firewall Management Center
Mitigation only
HIGH 7.5
CVE-2018-7920
Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200R006C10SPC300 devices have an…
Ar1200 Firmware
Mitigation only