|
196201
|
9.8 |
CRITICAL
Network
|
mpd_project stormshield
|
mpd stormshield_network_security
|
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of servi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7465
|
2024-11-21 14:37 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196202
|
8.3 |
HIGH
Network
|
shiba_project
|
shiba
|
All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load() of the package js-yaml instead of its secure replacement , safeLoad().
|
NVD-CWE-noinfo
|
CVE-2020-7738
|
2024-11-21 14:37 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196203
|
9.8 |
CRITICAL
Network
|
safetydance_project
|
safetydance
|
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7737
|
2024-11-21 14:37 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196204
|
9.8 |
CRITICAL
Network
|
bmoor_project
|
bmoor
|
The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7736
|
2024-11-21 14:37 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196205
|
6.6 |
MEDIUM
Network
|
ng-packagr_project
|
ng-packagr
|
The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.
|
CWE-78
OS Command
|
CVE-2020-7735
|
2024-11-21 14:37 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196206
|
8.2 |
HIGH
Network
|
arachnys
|
cabot
|
All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7734
|
2024-11-21 14:37 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196207
|
6.5 |
MEDIUM
Local
|
rapid7
|
appspider
|
In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This wo…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-7358
|
2024-11-21 14:37 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196208
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_x70_security_administrator
|
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-7532
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196209
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever R…
|
NVD-CWE-noinfo
|
CVE-2020-7531
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196210
|
8.8 |
HIGH
Network
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.
|
NVD-CWE-Other
|
CVE-2020-7530
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|