|
201941
|
7.2 |
HIGH
Network
|
mcafee
|
mvision_endpoint
|
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully co…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-7329
|
2024-11-21 14:37 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201942
|
7.2 |
HIGH
Network
|
mcafee
|
mvision_endpoint
|
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via impro…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-7328
|
2024-11-21 14:37 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201943
|
9.8 |
CRITICAL
Network
|
json-ptr_project
|
json-ptr
|
This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true.…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7766
|
2024-11-21 14:37 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201944
|
7.5 |
HIGH
Network
|
find-my-way_project
|
find-my-way
|
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a deni…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-7764
|
2024-11-21 14:37 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201945
|
7.5 |
HIGH
Network
|
jsreport
|
phantom-html-to-pdf
|
This affects the package phantom-html-to-pdf before 0.6.1.
|
CWE-22
Path Traversal
|
CVE-2020-7763
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201946
|
6.5 |
MEDIUM
Network
|
jsreport
|
jsreport-chrome-pdf
|
This affects the package jsreport-chrome-pdf before 1.10.0.
|
CWE-22
Path Traversal
|
CVE-2020-7762
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201947
|
5.3 |
MEDIUM
Network
|
absolunet
|
kafe
|
This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails.
|
NVD-CWE-noinfo
|
CVE-2020-7761
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201948
|
7.5 |
HIGH
Network
|
browserless
|
chrome
|
This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then s…
|
CWE-22
Path Traversal
|
CVE-2020-7758
|
2024-11-21 14:37 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201949
|
6.5 |
MEDIUM
Network
|
droppy_project
|
droppy
|
This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server.
|
CWE-22
Path Traversal
|
CVE-2020-7757
|
2024-11-21 14:37 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201950
|
9.8 |
CRITICAL
Network
|
vbulletin
|
vbulletin
|
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete …
|
CWE-94
Code Injection
|
CVE-2020-7373
|
2024-11-21 14:37 |
2020-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|