|
197351
|
9.8 |
CRITICAL
Network
|
jscover_project
|
jscover
|
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.
|
CWE-78
OS Command
|
CVE-2020-7623
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197352
|
9.8 |
CRITICAL
Network
|
ibm
|
strongloop_nginx_controller
|
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
|
CWE-78
OS Command
|
CVE-2020-7621
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197353
|
9.8 |
CRITICAL
Network
|
netease
|
pomelo-monitor
|
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
|
CWE-78
OS Command
|
CVE-2020-7620
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197354
|
9.8 |
CRITICAL
Network
|
get-git-data_project
|
get-git-data
|
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
|
CWE-78
OS Command
|
CVE-2020-7619
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197355
|
9.8 |
CRITICAL
Network
|
ini-parser_project
|
ini-parser
|
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7617
|
2024-11-21 14:37 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197356
|
9.8 |
CRITICAL
Network
|
objectcomputing
|
micronaut
|
All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed …
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-7611
|
2024-11-21 14:37 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197357
|
9.8 |
CRITICAL
Network
|
mongodb
|
bson
|
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialize…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-7610
|
2024-11-21 14:37 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197358
|
6.5 |
MEDIUM
Adjacent
|
gradle
|
plugin_publishing
|
All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with th…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-7599
|
2024-11-21 14:37 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197359
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_…
|
A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could cause a Reflective Cross-site Scriptin…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7482
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197360
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_…
|
A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could enable a successful Cross-site Scripti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7481
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|