|
200031
|
8.6 |
HIGH
Network
|
decal_project
|
decal
|
This affects all versions of package decal. The vulnerability is in the set function.
|
NVD-CWE-Other
|
CVE-2020-28449
|
2024-11-21 14:22 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200032
|
5.4 |
MEDIUM
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28001
|
2024-11-21 14:22 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200033
|
6.5 |
MEDIUM
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2020-27994
|
2024-11-21 14:22 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200034
|
9.8 |
CRITICAL
Network
|
moxa
|
edr-g903_firmware edr-g903-t_firmware edr-g902_firmware edr-g902-t_firmware edr-810-2gsfp_firmware edr-810-2gsfp-t_firmware edr-810-vpn-2gsfp_firmware edr-810-vpn-2gsfp-t_firmware
|
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Fir…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-28144
|
2024-11-21 14:22 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200035
|
6.8 |
MEDIUM
Network
|
indutny
|
elliptic
|
The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-28498
|
2024-11-21 14:22 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200036
|
7.3 |
HIGH
Network
|
totaljs
|
total.js
|
This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, l…
|
NVD-CWE-Other
|
CVE-2020-28495
|
2024-11-21 14:22 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200037
|
8.6 |
HIGH
Network
|
totaljs
|
total.js
|
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_proces…
|
CWE-78
OS Command
|
CVE-2020-28494
|
2024-11-21 14:22 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200038
|
5.3 |
MEDIUM
Network
|
palletsprojects fedoraproject
|
jinja fedora
|
This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-28493
|
2024-11-21 14:22 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200039
|
7.3 |
HIGH
Network
|
kill-process-on-port_project
|
kill-process-on-port
|
All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.
|
CWE-78
OS Command
|
CVE-2020-28426
|
2024-11-21 14:22 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200040
|
9.8 |
CRITICAL
Network
|
accel-ppp
|
accel-ppp
|
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS …
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-28194
|
2024-11-21 14:22 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|