|
196361
|
9.8 |
CRITICAL
Network
|
install-package_project umount_project
|
install-package umount
|
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
|
CWE-78
OS Command
|
CVE-2020-7628
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196362
|
9.8 |
CRITICAL
Network
|
node-key-sender_project
|
node-key-sender
|
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
|
CWE-78
OS Command
|
CVE-2020-7627
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196363
|
9.8 |
CRITICAL
Network
|
karma-mojo_project
|
karma-mojo
|
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
|
CWE-78
OS Command
|
CVE-2020-7626
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196364
|
9.8 |
CRITICAL
Network
|
op-browser_project
|
op-browser
|
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
|
CWE-78
OS Command
|
CVE-2020-7625
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196365
|
9.8 |
CRITICAL
Network
|
effect_project
|
effect
|
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
|
CWE-78
OS Command
|
CVE-2020-7624
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196366
|
9.8 |
CRITICAL
Network
|
jscover_project
|
jscover
|
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.
|
CWE-78
OS Command
|
CVE-2020-7623
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196367
|
9.8 |
CRITICAL
Network
|
ibm
|
strongloop_nginx_controller
|
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
|
CWE-78
OS Command
|
CVE-2020-7621
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196368
|
9.8 |
CRITICAL
Network
|
netease
|
pomelo-monitor
|
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
|
CWE-78
OS Command
|
CVE-2020-7620
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196369
|
9.8 |
CRITICAL
Network
|
get-git-data_project
|
get-git-data
|
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
|
CWE-78
OS Command
|
CVE-2020-7619
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196370
|
9.8 |
CRITICAL
Network
|
ini-parser_project
|
ini-parser
|
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7617
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|