|
200071
|
9.8 |
CRITICAL
Network
|
deferred-exec_project
|
deferred-exec
|
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js
|
CWE-77
Command Injection
|
CVE-2020-28438
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200072
|
9.8 |
CRITICAL
Network
|
google-cloudstorage-commands_project
|
google-cloudstorage-commands
|
This affects all versions of package google-cloudstorage-commands.
|
CWE-77
Command Injection
|
CVE-2020-28436
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200073
|
9.8 |
CRITICAL
Network
|
ffmpeg-sdk_project
|
ffmpeg-sdk
|
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
|
CWE-77
Command Injection
|
CVE-2020-28435
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200074
|
7.8 |
HIGH
Local
|
git-archive_project
|
git-archive
|
All versions of package git-archive are vulnerable to Command Injection via the exports function.
|
CWE-77
Command Injection
|
CVE-2020-28422
|
2024-11-21 14:22 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200075
|
9.8 |
CRITICAL
Network
|
form
|
form.io
|
A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was …
|
CWE-74
Injection
|
CVE-2020-28246
|
2024-11-21 14:22 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200076
|
8.8 |
HIGH
Network
|
cgal debian
|
computational_geometry_algorithms_library debian_linux
|
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
|
-
|
CVE-2020-28604
|
2024-11-21 14:22 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200077
|
8.8 |
HIGH
Network
|
cgal debian
|
computational_geometry_algorithms_library debian_linux
|
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
|
-
|
CVE-2020-28603
|
2024-11-21 14:22 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200078
|
8.8 |
HIGH
Network
|
cgal debian
|
computational_geometry_algorithms_library debian_linux
|
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
|
-
|
CVE-2020-28602
|
2024-11-21 14:22 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200079
|
7.2 |
HIGH
Network
|
hisiphp
|
hisiphp
|
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user exe…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-28062
|
2024-11-21 14:22 |
2022-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200080
|
4.3 |
MEDIUM
Network
|
osu
|
ohio_supercomputer_center_open_ondemand
|
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-27958
|
2024-11-21 14:22 |
2022-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|