Vulnerabilities in HackerOne

470 results
Vexday analysis

Com 470 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o perfil de risco ativo do HackerOne situa-se abaixo da média geral do catálogo, sem registros de exploração confirmada no momento. A ausência de vulnerabilidades críticas e de novos registros nos últimos 90 dias sugere estabilidade recente no volume de descobertas, embora a existência de uma PoC pública mereça atenção por ampliar a superfície de exploração potencial. O CWE-311 — relacionado à ausência ou proteção inadequada de dados sensíveis em trânsito ou armazenamento — representa o tipo de falha mais recorrente, indicando uma área técnica que justifica revisão continuada de controles criptográficos. A CVE mais relevante no momento, CVE-2017-0901, apresenta EPSS de 0,2944, sinalizando probabilidade não desprezível de exploração e recomendando priorização no processo de remediação, mesmo sem confirmação de exploração ativa catalogada.

CVE-2016-10563—During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attacEPSS 0.8%CVE-2018-16480—A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanEPSS 0.8%CVE-2017-16207—discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.EPSS 0.7%CVE-2017-16035—The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from apEPSS 0.7%CVE-2016-10680—adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources oEPSS 0.7%CVE-2018-16481—A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absEPSS 0.7%CVE-2018-3759—private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the sockEPSS 0.7%CVE-2016-10537—backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your REPSS 0.7%CVE-2017-16041—ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.7%CVE-2016-10549—Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration wEPSS 0.6%CVE-2016-10592—jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.6%CVE-2018-3716—simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.EPSS 0.6%CVE-2018-16484—A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escEPSS 0.6%CVE-2016-10618—node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.6%CVE-2016-10594—ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources EPSS 0.6%CVE-2016-10641—node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.6%CVE-2016-10578—unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves EPSS 0.6%CVE-2016-10568—geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data EPSS 0.6%CVE-2016-10630—install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.5%CVE-2016-10610—unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attEPSS 0.5%