Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cordova vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2016-6799
Product: Apache Cordova Android 5.2.2 and previous versions. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximum of four ...
Apache Cordova
7.5
CVSSv2
CVE-2015-5207
Apache Cordova iOS prior to 4.0.0 might allow malicious users to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.
Apache Cordova
6.4
CVSSv2
CVE-2014-3500
Apache Cordova Android prior to 3.5.1 allows remote malicious users to change the start page via a crafted intent URL.
Apache Cordova
5
CVSSv2
CVE-2015-8320
Apache Cordova-Android prior to 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for malicious users to conduct bridge hijacking attacks by predicting a value.
Apache Cordova
2.1
CVSSv2
CVE-2020-11990
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with...
Apache Cordova 4.1.0
4.3
CVSSv2
CVE-2014-3501
Apache Cordova Android prior to 3.5.1 allows remote malicious users to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.
Apache Cordova 3.5.0
4.3
CVSSv2
CVE-2014-3502
Apache Cordova Android prior to 3.5.1 allows remote malicious users to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
Apache Cordova 3.5.0
4.3
CVSSv2
CVE-2015-5204
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android prior to 1.3.0 allows remote malicious users to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.
Apache Cordova File Transfer
4.6
CVSSv2
CVE-2021-21315
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem...
Systeminformation Systeminformation
Apache Cordova 10.0.0
15 Github repositories
7.5
CVSSv2
CVE-2019-0219
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Apache Cordova Inappbrowser
Oracle Instantis Enterprisetrack 17.1
Oracle Instantis Enterprisetrack 17.2
Oracle Instantis Enterprisetrack 17.3
Oracle Retail Xstore Point Of Service 16.0.6
Oracle Retail Xstore Point Of Service 17.0.4
Oracle Retail Xstore Point Of Service 18.0.3
Oracle Retail Xstore Point Of Service 19.0.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
race condition
CVE-2024-4249
CVE-2024-4244
CVE-2023-20198
TCP
CVE-2022-48648
CVE-2022-48636
CVE-2024-21345
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »