|
196011
|
4.8 |
MEDIUM
Network
|
eaton
|
5p_850_firmware
|
An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7915
|
2024-11-21 14:38 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196012
|
9.8 |
CRITICAL
Network
|
get-npm-package-version_project
|
get-npm-package-version
|
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
|
CWE-77
Command Injection
|
CVE-2020-7795
|
2024-11-21 14:37 |
2022-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196013
|
9.8 |
CRITICAL
Network
|
node-import_project
|
node-import
|
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located …
|
NVD-CWE-noinfo
|
CVE-2020-7678
|
2024-11-21 14:37 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196014
|
9.8 |
CRITICAL
Network
|
thenify_project debian fedoraproject
|
thenify debian_linux fedora
|
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any san…
|
NVD-CWE-noinfo
|
CVE-2020-7677
|
2024-11-21 14:37 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196015
|
4.9 |
MEDIUM
Network
|
snyk
|
broker
|
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-7649
|
2024-11-21 14:37 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196016
|
7.8 |
HIGH
Local
|
grunt-util-property_project
|
grunt-util-property
|
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7641
|
2024-11-21 14:37 |
2022-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196017
|
8.8 |
HIGH
Network
|
schneider-electric
|
modicon_m340_bmxp342020_firmware 140cpu65_firmware tsxp57_firmware bmxnoc0401_firmware bmxnoe01_firmware bmxnor0200h_firmware 140noe77111_firmware 140noc78000_firmware tsxety5…
|
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user …
|
CWE-352
Origin Validation Error
|
CVE-2020-7534
|
2024-11-21 14:37 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196018
|
9.8 |
CRITICAL
Network
|
wowsoft
|
printchaser
|
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. …
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7883
|
2024-11-21 14:37 |
2021-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196019
|
9.8 |
CRITICAL
Network
|
4nb
|
videooffice
|
An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-7878
|
2024-11-21 14:37 |
2021-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196020
|
8.8 |
HIGH
Network
|
douzone
|
neors
|
The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper paramete…
|
CWE-20
Improper Input Validation
|
CVE-2020-7880
|
2024-11-21 14:37 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|