|
208921
|
9.8 |
CRITICAL
Network
|
ion-parser_project
|
ion-parser
|
This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-28462
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208922
|
9.8 |
CRITICAL
Network
|
js-ini_project
|
js-ini
|
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-28461
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208923
|
6.1 |
MEDIUM
Network
|
markdown-it-decorate_project
|
markdown-it-decorate
|
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28459
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208924
|
6.1 |
MEDIUM
Network
|
markdown-it-toc_project
|
markdown-it-toc
|
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28455
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208925
|
9.8 |
CRITICAL
Network
|
xopen_project
|
xopen
|
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)
|
CWE-77
Command Injection
|
CVE-2020-28447
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208926
|
9.8 |
CRITICAL
Network
|
ntesseract_project
|
ntesseract
|
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
|
CWE-77
Command Injection
|
CVE-2020-28446
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208927
|
9.8 |
CRITICAL
Network
|
npm-help_project
|
npm-help
|
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.
|
CWE-77
Command Injection
|
CVE-2020-28445
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208928
|
9.8 |
CRITICAL
Network
|
sonar-wrapper_project
|
sonar-wrapper
|
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
|
CWE-77
Command Injection
|
CVE-2020-28443
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208929
|
9.8 |
CRITICAL
Network
|
conf-cfg-ini_project
|
conf-cfg-ini
|
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This …
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-28441
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208930
|
9.8 |
CRITICAL
Network
|
deferred-exec_project
|
deferred-exec
|
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js
|
CWE-77
Command Injection
|
CVE-2020-28438
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|