Search Results (7991 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-3949 1 Tp-link 2 Tl-r600vpn, Tl-r600vpn Firmware 2024-11-21 7.5 High
An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted URL can cause a directory traversal, resulting in the disclosure of sensitive system files. An attacker can send either an unauthenticated or an authenticated web request to trigger this vulnerability.
CVE-2018-3822 1 Elastic 1 X-pack 2024-11-21 9.8 Critical
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.
CVE-2018-3787 1 Simplehttpserver Project 1 Simplehttpserver 2024-11-21 7.5 High
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
CVE-2018-3770 1 Markdown-pdf Project 1 Markdown-pdf 2024-11-21 5.5 Medium
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
CVE-2018-3766 1 Buttle Project 1 Buttle 2024-11-21 7.5 High
Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.
CVE-2018-3760 3 Debian, Redhat, Sprockets Project 6 Debian Linux, Cloudforms, Cloudforms Managementengine and 3 more 2024-11-21 N/A
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.
CVE-2018-3758 1 Express-cart Project 1 Express-cart 2024-11-21 8.8 High
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
CVE-2018-3744 1 Html-pages Project 1 Html-pages 2024-11-21 9.8 Critical
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
CVE-2018-3734 1 Stattic Project 1 Stattic 2024-11-21 7.5 High
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path.
CVE-2018-3733 1 Crud-file-server Project 1 Crud-file-server 2024-11-21 7.5 High
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
CVE-2018-3732 1 Resolve-path Project 1 Resolve-path 2024-11-21 7.5 High
resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths with certain special characters, which allows a malicious user to read content of any file with known path.
CVE-2018-3731 1 Public.js Project 1 Public.js 2024-11-21 7.5 High
public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
CVE-2018-3730 1 Mcstatic Project 1 Mcstatic 2024-11-21 7.5 High
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
CVE-2018-3729 1 Localhost-now Project 1 Localhost-now 2024-11-21 7.5 High
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CVE-2018-3727 1 626 Project 1 626 2024-11-21 7.5 High
626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CVE-2018-3725 1 Hekto Project 1 Hekto 2024-11-21 7.5 High
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CVE-2018-3724 1 General-file-server Project 1 General-file-server 2024-11-21 N/A
general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path.
CVE-2018-3715 1 Glance Project 1 Glance 2024-11-21 6.5 Medium
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
CVE-2018-3714 1 Node-srv Project 1 Node-srv 2024-11-21 6.5 Medium
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
CVE-2018-3713 1 Angular-http-server Project 1 Angular-http-server 2024-11-21 6.5 Medium
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.