|
196781
|
9.8 |
CRITICAL
Network
|
karma-mojo_project
|
karma-mojo
|
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
|
CWE-78
OS Command
|
CVE-2020-7626
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196782
|
9.8 |
CRITICAL
Network
|
op-browser_project
|
op-browser
|
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
|
CWE-78
OS Command
|
CVE-2020-7625
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196783
|
9.8 |
CRITICAL
Network
|
effect_project
|
effect
|
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
|
CWE-78
OS Command
|
CVE-2020-7624
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196784
|
9.8 |
CRITICAL
Network
|
jscover_project
|
jscover
|
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.
|
CWE-78
OS Command
|
CVE-2020-7623
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196785
|
9.8 |
CRITICAL
Network
|
ibm
|
strongloop_nginx_controller
|
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
|
CWE-78
OS Command
|
CVE-2020-7621
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196786
|
9.8 |
CRITICAL
Network
|
netease
|
pomelo-monitor
|
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
|
CWE-78
OS Command
|
CVE-2020-7620
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196787
|
9.8 |
CRITICAL
Network
|
get-git-data_project
|
get-git-data
|
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
|
CWE-78
OS Command
|
CVE-2020-7619
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196788
|
9.8 |
CRITICAL
Network
|
ini-parser_project
|
ini-parser
|
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7617
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196789
|
9.8 |
CRITICAL
Network
|
objectcomputing
|
micronaut
|
All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed …
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-7611
|
2024-11-21 14:37 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196790
|
9.8 |
CRITICAL
Network
|
mongodb
|
bson
|
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialize…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-7610
|
2024-11-21 14:37 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|