Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ins vulnerabilities and exploits
(subscribe to this query)
8.6
CVSSv3
CVE-2023-48431
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC serve...
Siemens Sinec Ins 1.0
Siemens Sinec Ins
5.3
CVSSv3
CVE-2022-32222
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x before 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to O...
Nodejs Node.js
Siemens Sinec Ins 1.0
Siemens Sinec Ins
1 Github repository
5.9
CVSSv3
CVE-2020-28168
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Axios Axios
Siemens Sinec Ins 1.0
Siemens Sinec Ins
2 Github repositories
5.9
CVSSv3
CVE-2014-7242
The SumaHo application 3.0.0 and previous versions for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and previous versions for Android allow man-in-the-middle malicious users to spoof servers and obtain sensitive information...
Ms-ins Sumaho Driving Capability Diagnosis
Ms-ins Sumaho
7.5
CVSSv3
CVE-2021-3749
axios is vulnerable to Inefficient Regular Expression Complexity
Axios Axios
Siemens Sinec Ins 1.0
Siemens Sinec Ins
Oracle Goldengate
3 Github repositories
6.5
CVSSv3
CVE-2022-0155
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
Follow-redirects Project Follow-redirects
Siemens Sinec Ins 1.0
Siemens Sinec Ins
7 Github repositories
9.1
CVSSv3
CVE-2022-35255
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa...
Nodejs Node.js
Siemens Sinec Ins 1.0
Siemens Sinec Ins
Debian Debian Linux 11.0
7.5
CVSSv3
CVE-2020-7793
The package ua-parser-js prior to 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
Ua-parser-js Project Ua-parser-js
Siemens Sinec Ins 1.0
Siemens Sinec Ins
6.5
CVSSv3
CVE-2022-35256
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
Nodejs Node.js
Llhttp Llhttp
Siemens Sinec Ins 1.0
Siemens Sinec Ins
Debian Debian Linux 11.0
6.1
CVSSv3
CVE-2022-0235
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Node-fetch Project Node-fetch
Siemens Sinec Ins 1.0
Siemens Sinec Ins
Debian Debian Linux 10.0
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »