|
198971
|
9.8 |
CRITICAL
Network
|
safetydance_project
|
safetydance
|
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7737
|
2024-11-21 14:37 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198972
|
9.8 |
CRITICAL
Network
|
bmoor_project
|
bmoor
|
The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7736
|
2024-11-21 14:37 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198973
|
6.6 |
MEDIUM
Network
|
ng-packagr_project
|
ng-packagr
|
The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.
|
CWE-78
OS Command
|
CVE-2020-7735
|
2024-11-21 14:37 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198974
|
8.2 |
HIGH
Network
|
arachnys
|
cabot
|
All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7734
|
2024-11-21 14:37 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198975
|
6.5 |
MEDIUM
Local
|
rapid7
|
appspider
|
In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This wo…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-7358
|
2024-11-21 14:37 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198976
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_x70_security_administrator
|
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-7532
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198977
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever R…
|
NVD-CWE-noinfo
|
CVE-2020-7531
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198978
|
8.8 |
HIGH
Network
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.
|
NVD-CWE-Other
|
CVE-2020-7530
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198979
|
5.5 |
MEDIUM
Local
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place …
|
-
|
CVE-2020-7529
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198980
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ…
|
-
|
CVE-2020-7528
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|