Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2017-16139

    jikes is a file server. jikes is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Accessible files are restricted to files with .htm and .js extensions.... Read more

    Affected Products : jikes
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16138

    The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.... Read more

    Affected Products : mime
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2017-16137

    The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.... Read more

    Affected Products : debug
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16136

    method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when speciall... Read more

    Affected Products : method-override
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16135

    serverzyy is a static file server. serverzyy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : serverzyy
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16134

    http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : http_static_simple
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16133

    goserv is an http server. goserv is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : goserv
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16132

    simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : simple-npm-registry
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16131

    unicorn-list is a web framework. unicorn-list is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : unicorn-list
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16130

    exxxxxxxxxxx is an Http eX Frame Google Style JavaScript Guide. exxxxxxxxxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Accessible files are restricted to those with a file extens... Read more

    Affected Products : exxxxxxxxxxx
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2017-16129

    The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing ... Read more

    Affected Products : superagent
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2017-16128

    The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.... Read more

    Affected Products : npm-script-demo
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2017-16127

    The module pandora-doomsday infects other modules. It's since been unpublished from the registry.... Read more

    Affected Products : pandora-doomsday
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2017-16126

    The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is known to record and track user information. The module tracks the following information. Source IP process.versions process.platform How t... Read more

    Affected Products : botbait
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16125

    rtcmulticonnection-client is a signaling implementation for RTCMultiConnection.js, a multi-session manager. rtcmulticonnection-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : rtcmulticonnection-client
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16124

    node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : node-server-forfront
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16123

    welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : welcomyzt
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16122

    cuciuci is a simple fileserver. cuciuci is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : cuciuci
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16121

    datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : datachannel-client
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-16120

    liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more

    Affected Products : liyujing
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292803 Results