Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache cordova vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2015-5207
Apache Cordova iOS prior to 4.0.0 might allow malicious users to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.
Apache Cordova
NA
CVE-2015-8320
Apache Cordova-Android prior to 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for malicious users to conduct bridge hijacking attacks by predicting a value.
Apache Cordova
NA
CVE-2014-3500
Apache Cordova Android prior to 3.5.1 allows remote malicious users to change the start page via a crafted intent URL.
Apache Cordova
7.4
CVSSv3
CVE-2017-3160
After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https, it is vulnerable to a MiTM and the Gradle executable is not s...
Apache Cordova
NA
CVE-2014-3501
Apache Cordova Android prior to 3.5.1 allows remote malicious users to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.
Apache Cordova 3.5.0
NA
CVE-2014-3502
Apache Cordova Android prior to 3.5.1 allows remote malicious users to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
Apache Cordova 3.5.0
3.3
CVSSv3
CVE-2020-11990
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with...
Apache Cordova 4.1.0
NA
CVE-2015-5204
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android prior to 1.3.0 allows remote malicious users to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.
Apache Cordova File Transfer
7.8
CVSSv3
CVE-2021-21315
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem...
Systeminformation Systeminformation
Apache Cordova 10.0.0
16 Github repositories
9.8
CVSSv3
CVE-2019-0219
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Apache Cordova Inappbrowser
Oracle Instantis Enterprisetrack 17.1
Oracle Instantis Enterprisetrack 17.2
Oracle Instantis Enterprisetrack 17.3
Oracle Retail Xstore Point Of Service 16.0.6
Oracle Retail Xstore Point Of Service 17.0.4
Oracle Retail Xstore Point Of Service 18.0.3
Oracle Retail Xstore Point Of Service 19.0.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4654
CVE-2023-49606
encryption
NULL pointer dereference
CVE-2024-4439
CVE-2024-4649
race condition
CVE-2024-27202
CVE-2024-34566
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »