Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache cordova vulnerabilities and exploits
(subscribe to this query)
231
VMScore
CVE-2015-1835
Apache Cordova Android prior to 3.7.2 and 4.x prior to 4.0.2, when an application does not set explicit values in config.xml, allows remote malicious users to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
Apache Cordova 4.0.1
Apache Cordova 4.0.0
Apache Cordova
445
VMScore
CVE-2014-0072
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) prior to 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 up to and including 2.9.0 might allow remote malicious users to spoof SSL servers by lever...
Apache Cordova File Transfer
Apache Cordova
668
VMScore
CVE-2014-0073
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) prior to 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 up to and including 2.9.0 does not properly validate callback identifiers, which allo...
Apache Cordova In-app-browser
Apache Cordova
668
VMScore
CVE-2014-1881
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions allow remote malicious users to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain a...
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.3.0
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.5.0
Adobe Phonegap 2.8.0
Adobe Phonegap
Adobe Phonegap 2.3.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
668
VMScore
CVE-2014-1882
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions allow remote malicious users to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and directly accesses...
Adobe Phonegap 2.2.0
Adobe Phonegap 2.3.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.5.0
Adobe Phonegap
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.8.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.3.0
668
VMScore
CVE-2014-1884
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote malicious users to bypass intended device-resource restrictions via content that is accessed (1) in a...
Apache Cordova 3.0.0
Apache Cordova 3.2.0
Apache Cordova 3.3.0
Apache Cordova 3.1.0
Apache Cordova
Adobe Phonegap 2.0.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.8.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.5.0
Adobe Phonegap
Adobe Phonegap 2.3.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
668
VMScore
CVE-2012-6637
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions do not anchor the end of domain-name regular expressions, which allows remote malicious users to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as...
Apache Cordova 3.3.0
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.3.0
Adobe Phonegap 2.5.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.9.0
Adobe Phonegap 2.4.0
Adobe Phonegap
Adobe Phonegap 2.8.0
Adobe Phonegap 2.8.1
516
VMScore
CVE-2017-3160
After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https, it is vulnerable to a MiTM and the Gradle executable is not s...
Apache Cordova
445
VMScore
CVE-2016-6799
Product: Apache Cordova Android 5.2.2 and previous versions. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximum of four ...
Apache Cordova
570
VMScore
CVE-2014-3500
Apache Cordova Android prior to 3.5.1 allows remote malicious users to change the start page via a crafted intent URL.
Apache Cordova
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »