|
198251
|
5.3 |
MEDIUM
Network
|
express-validators_project
|
express-validators
|
All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-7767
|
2024-11-21 14:37 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198252
|
7.2 |
HIGH
Network
|
mcafee
|
mvision_endpoint
|
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully co…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-7329
|
2024-11-21 14:37 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198253
|
7.2 |
HIGH
Network
|
mcafee
|
mvision_endpoint
|
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via impro…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-7328
|
2024-11-21 14:37 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198254
|
9.8 |
CRITICAL
Network
|
json-ptr_project
|
json-ptr
|
This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true.…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7766
|
2024-11-21 14:37 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198255
|
7.5 |
HIGH
Network
|
find-my-way_project
|
find-my-way
|
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a deni…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-7764
|
2024-11-21 14:37 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198256
|
7.5 |
HIGH
Network
|
jsreport
|
phantom-html-to-pdf
|
This affects the package phantom-html-to-pdf before 0.6.1.
|
CWE-22
Path Traversal
|
CVE-2020-7763
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198257
|
6.5 |
MEDIUM
Network
|
jsreport
|
jsreport-chrome-pdf
|
This affects the package jsreport-chrome-pdf before 1.10.0.
|
CWE-22
Path Traversal
|
CVE-2020-7762
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198258
|
5.3 |
MEDIUM
Network
|
absolunet
|
kafe
|
This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails.
|
NVD-CWE-noinfo
|
CVE-2020-7761
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198259
|
7.5 |
HIGH
Network
|
browserless
|
chrome
|
This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then s…
|
CWE-22
Path Traversal
|
CVE-2020-7758
|
2024-11-21 14:37 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198260
|
6.5 |
MEDIUM
Network
|
droppy_project
|
droppy
|
This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server.
|
CWE-22
Path Traversal
|
CVE-2020-7757
|
2024-11-21 14:37 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|