Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache cordova vulnerabilities and exploits
(subscribe to this query)
4.4
CVSSv3
CVE-2015-5208
Apache Cordova iOS prior to 4.0.0 allows remote malicious users to execute arbitrary plugins via a link.
Apache Cordova
7.5
CVSSv3
CVE-2016-6799
Product: Apache Cordova Android 5.2.2 and previous versions. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximum of four ...
Apache Cordova
7.4
CVSSv3
CVE-2017-3160
After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https, it is vulnerable to a MiTM and the Gradle executable is not s...
Apache Cordova
NA
CVE-2014-3500
Apache Cordova Android prior to 3.5.1 allows remote malicious users to change the start page via a crafted intent URL.
Apache Cordova
3.3
CVSSv3
CVE-2020-11990
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with...
Apache Cordova 4.1.0
NA
CVE-2014-3501
Apache Cordova Android prior to 3.5.1 allows remote malicious users to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.
Apache Cordova 3.5.0
NA
CVE-2014-3502
Apache Cordova Android prior to 3.5.1 allows remote malicious users to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
Apache Cordova 3.5.0
NA
CVE-2015-5204
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android prior to 1.3.0 allows remote malicious users to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.
Apache Cordova File Transfer
7.8
CVSSv3
CVE-2021-21315
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem...
Systeminformation Systeminformation
Apache Cordova 10.0.0
16 Github repositories
9.8
CVSSv3
CVE-2019-0219
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Apache Cordova Inappbrowser
Oracle Instantis Enterprisetrack 17.1
Oracle Instantis Enterprisetrack 17.2
Oracle Instantis Enterprisetrack 17.3
Oracle Retail Xstore Point Of Service 16.0.6
Oracle Retail Xstore Point Of Service 17.0.4
Oracle Retail Xstore Point Of Service 18.0.3
Oracle Retail Xstore Point Of Service 19.0.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »