|
198921
|
9.8 |
CRITICAL
Network
|
jooby
|
jooby
|
This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused fo…
|
NVD-CWE-Other
|
CVE-2020-7622
|
2024-11-21 14:37 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198922
|
5.3 |
MEDIUM
Network
|
dot_project
|
dot
|
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7639
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198923
|
5.3 |
MEDIUM
Network
|
confinit_project
|
confinit
|
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7638
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198924
|
5.3 |
MEDIUM
Network
|
class-transformer_project
|
class-transformer
|
class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __pr…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7637
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198925
|
9.8 |
CRITICAL
Network
|
adb-driver_project
|
adb-driver
|
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.
|
CWE-78
OS Command
|
CVE-2020-7636
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198926
|
9.8 |
CRITICAL
Network
|
compass-compile_project
|
compass-compile
|
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
|
CWE-78
OS Command
|
CVE-2020-7635
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198927
|
9.8 |
CRITICAL
Network
|
heroku-addonpool_project
|
heroku-addonpool
|
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
|
CWE-78
OS Command
|
CVE-2020-7634
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198928
|
9.8 |
CRITICAL
Network
|
apiconnect-cli-plugins_project
|
apiconnect-cli-plugins
|
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
|
CWE-78
OS Command
|
CVE-2020-7633
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198929
|
9.8 |
CRITICAL
Network
|
node-mpv_project
|
node-mpv
|
node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
|
CWE-78
OS Command
|
CVE-2020-7632
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198930
|
9.8 |
CRITICAL
Network
|
diskusage-ng_project
|
diskusage-ng
|
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
|
CWE-78
OS Command
|
CVE-2020-7631
|
2024-11-21 14:37 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|