|
196141
|
8.8 |
HIGH
Network
|
tobesoft
|
xplatform
|
Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://
|
CWE-20
Improper Input Validation
|
CVE-2020-7841
|
2024-11-21 14:37 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196142
|
9.8 |
CRITICAL
Network
|
y18n_project oracle siemens
|
y18n graalvm sinec_infrastructure_network_services
|
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7774
|
2024-11-21 14:37 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196143
|
6.1 |
MEDIUM
Network
|
markdown-it-highlightjs_project
|
markdown-it-highlightjs
|
This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const mar…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7773
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196144
|
5.3 |
MEDIUM
Network
|
google
|
firebase\/util
|
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwr…
|
NVD-CWE-noinfo
|
CVE-2020-7765
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196145
|
9.8 |
CRITICAL
Network
|
doc-path_project
|
doc-path
|
This affects the package doc-path before 2.1.2.
|
NVD-CWE-noinfo
|
CVE-2020-7772
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196146
|
9.8 |
CRITICAL
Network
|
sugarcrm
|
sugarcrm
|
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenti…
|
CWE-94 CWE-20
Code Injection Improper Input Validation
|
CVE-2020-7472
|
2024-11-21 14:37 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196147
|
9.8 |
CRITICAL
Network
|
json8_project
|
json8
|
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype po…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7770
|
2024-11-21 14:37 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196148
|
4.8 |
MEDIUM
Network
|
mcafee
|
endpoint_security
|
Cross site scripting vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows administrators to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7333
|
2024-11-21 14:37 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196149
|
8.8 |
HIGH
Network
|
mcafee
|
endpoint_security
|
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to …
|
CWE-352
Origin Validation Error
|
CVE-2020-7332
|
2024-11-21 14:37 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196150
|
7.8 |
HIGH
Local
|
mcafee
|
endpoint_security
|
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully craf…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-7331
|
2024-11-21 14:37 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|