|
196241
|
5.3 |
MEDIUM
Network
|
sockjs_project
|
sockjs
|
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-7693
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196242
|
9.1 |
CRITICAL
Network
|
google
|
oauth_client_library_for_java
|
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarante…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7692
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196243
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7458
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196244
|
8.1 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS sock…
|
CWE-362 CWE-416 CWE-662
Race Condition Use After Free Improper Synchronization
|
CVE-2020-7457
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196245
|
6.1 |
MEDIUM
Network
|
parall
|
jspdf
|
In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7691
|
2024-11-21 14:37 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196246
|
6.1 |
MEDIUM
Network
|
parall
|
jspdf
|
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7690
|
2024-11-21 14:37 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196247
|
9.8 |
CRITICAL
Network
|
nexaweb
|
nexacro_14 nexacro_17
|
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be lev…
|
CWE-20
Improper Input Validation
|
CVE-2020-7821
|
2024-11-21 14:37 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196248
|
9.8 |
CRITICAL
Network
|
nexaweb
|
nexacro_14 nexacro_17
|
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can…
|
CWE-20
Improper Input Validation
|
CVE-2020-7820
|
2024-11-21 14:37 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196249
|
7.8 |
HIGH
Local
|
mversion_project
|
mversion
|
The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
|
CWE-78
OS Command
|
CVE-2020-7688
|
2024-11-21 14:37 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196250
|
7.5 |
HIGH
Network
|
node.bcrypt.js_project
|
node.bcrypt.js
|
Data is truncated wrong when its length is greater than 255 bytes.
|
CWE-190 CWE-327
Integer Overflow or Wraparound Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-7689
|
2024-11-21 14:37 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|