Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cordova vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2015-5208
Apache Cordova iOS prior to 4.0.0 allows remote malicious users to execute arbitrary plugins via a link.
Apache Cordova
384
VMScore
CVE-2015-5256
Apache Cordova-Android prior to 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows malicious users to bypass intended access restrictions via a crafted URI.
Apache Cordova
446
VMScore
CVE-2015-8320
Apache Cordova-Android prior to 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for malicious users to conduct bridge hijacking attacks by predicting a value.
Apache Cordova
570
VMScore
CVE-2014-3500
Apache Cordova Android prior to 3.5.1 allows remote malicious users to change the start page via a crafted intent URL.
Apache Cordova
188
VMScore
CVE-2020-11990
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with...
Apache Cordova 4.1.0
383
VMScore
CVE-2014-3501
Apache Cordova Android prior to 3.5.1 allows remote malicious users to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.
Apache Cordova 3.5.0
383
VMScore
CVE-2014-3502
Apache Cordova Android prior to 3.5.1 allows remote malicious users to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
Apache Cordova 3.5.0
383
VMScore
CVE-2015-5204
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android prior to 1.3.0 allows remote malicious users to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.
Apache Cordova File Transfer
413
VMScore
CVE-2021-21315
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem...
Systeminformation Systeminformation
Apache Cordova 10.0.0
16 Github repositories
668
VMScore
CVE-2019-0219
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Apache Cordova Inappbrowser
Oracle Instantis Enterprisetrack 17.1
Oracle Instantis Enterprisetrack 17.2
Oracle Instantis Enterprisetrack 17.3
Oracle Retail Xstore Point Of Service 16.0.6
Oracle Retail Xstore Point Of Service 17.0.4
Oracle Retail Xstore Point Of Service 18.0.3
Oracle Retail Xstore Point Of Service 19.0.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »