|
200071
|
9.8 |
CRITICAL
Network
|
djv_project
|
djv
|
This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.
|
CWE-94
Code Injection
|
CVE-2020-28464
|
2024-11-21 14:22 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200072
|
6.5 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
|
CWE-89
SQL Injection
|
CVE-2020-28413
|
2024-11-21 14:22 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200073
|
7.5 |
HIGH
Network
|
tenda
|
ac1200_firmware
|
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-28095
|
2024-11-21 14:22 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200074
|
6.1 |
MEDIUM
Network
|
sapplica
|
sentrifugo
|
Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For HTTP header during the login process. When an administrator looks at logs, the …
|
CWE-79
Cross-site Scripting
|
CVE-2020-28365
|
2024-11-21 14:22 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200075
|
9.8 |
CRITICAL
Network
|
libnested_project
|
libnested
|
Prototype pollution vulnerability in 'libnested' versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-Other
|
CVE-2020-28283
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200076
|
9.8 |
CRITICAL
Network
|
getobject_project
|
getobject
|
Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-Other
|
CVE-2020-28282
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200077
|
9.8 |
CRITICAL
Network
|
set-object-value_project
|
set-object-value
|
Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28281
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200078
|
9.8 |
CRITICAL
Network
|
predefine_project
|
predefine
|
Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28280
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200079
|
9.8 |
CRITICAL
Network
|
flattenizer_project
|
flattenizer
|
Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28279
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200080
|
9.8 |
CRITICAL
Network
|
shvl_project
|
shvl
|
Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28278
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|