Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Evilpacket

#16858of 53,622
15.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2019-13824
6.1
2019-05-29
Verdaccio · Verdaccio · CVE-2019-14772
**Name of the Vulnerable Software and Affected Versions** verdaccio versions prior to 3.12.0 **Description** The issue is a Cross-Site Scripting (XSS) vulnerability, where malicious packages with JavaScript content can be executed in the User Interface, potentially stealing user credentials. **Recommendations** For versions prior to 3.12.0, upgrade to version 3.12.0 or later, or migrate to a major version 4.0.0 or later to fix the issue. At the moment, there is no workaround available without upgrading.
PT-2018-6070
9.8
2018-06-04
Growl · Growl · CVE-2017-16042
Name of the Vulnerable Software and Affected Versions: growl versions prior to 1.10.2 Description: The issue allows for arbitrary command execution due to improper input sanitization before passing it to a shell command. Recommendations: Update to version 1.10.2 or later.