|
196661
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7458
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196662
|
8.1 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS sock…
|
CWE-362 CWE-416 CWE-662
Race Condition Use After Free Improper Synchronization
|
CVE-2020-7457
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196663
|
6.1 |
MEDIUM
Network
|
parall
|
jspdf
|
In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7691
|
2024-11-21 14:37 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196664
|
6.1 |
MEDIUM
Network
|
parall
|
jspdf
|
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7690
|
2024-11-21 14:37 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196665
|
9.8 |
CRITICAL
Network
|
nexaweb
|
nexacro_14 nexacro_17
|
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be lev…
|
CWE-20
Improper Input Validation
|
CVE-2020-7821
|
2024-11-21 14:37 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196666
|
9.8 |
CRITICAL
Network
|
nexaweb
|
nexacro_14 nexacro_17
|
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can…
|
CWE-20
Improper Input Validation
|
CVE-2020-7820
|
2024-11-21 14:37 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196667
|
7.8 |
HIGH
Local
|
mversion_project
|
mversion
|
The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
|
CWE-78
OS Command
|
CVE-2020-7688
|
2024-11-21 14:37 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196668
|
7.5 |
HIGH
Network
|
node.bcrypt.js_project
|
node.bcrypt.js
|
Data is truncated wrong when its length is greater than 255 bytes.
|
CWE-190 CWE-327
Integer Overflow or Wraparound Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-7689
|
2024-11-21 14:37 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196669
|
7.8 |
HIGH
Local
|
hmtalk
|
daoffice dava\+ daview_indy
|
A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker to cause an arbitrary code execution on an affected device.n…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7816
|
2024-11-21 14:37 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196670
|
6.1 |
MEDIUM
Network
|
rapid7
|
metasploit
|
Cross-site Scripting (XSS) vulnerability in the 'notes' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target store an…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7355
|
2024-11-21 14:37 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|