|
196081
|
8.8 |
HIGH
Network
|
onstove
|
stove
|
A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrary code when the user access to crafted web page. T…
|
CWE-20
Improper Input Validation
|
CVE-2020-7838
|
2024-11-21 14:37 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196082
|
9.8 |
CRITICAL
Network
|
connection-tester_project
|
connection-tester
|
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
|
CWE-78
OS Command
|
CVE-2020-7781
|
2024-11-21 14:37 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196083
|
8.8 |
HIGH
Network
|
polarisoffice
|
polaris_ml_report
|
An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strin…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7837
|
2024-11-21 14:37 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196084
|
7.5 |
HIGH
Network
|
i18n_project
|
i18n
|
This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs.
|
NVD-CWE-noinfo
|
CVE-2020-7791
|
2024-11-21 14:37 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196085
|
7.5 |
HIGH
Network
|
ua-parser-js_project siemens
|
ua-parser-js sinec_ins
|
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
|
NVD-CWE-Other
|
CVE-2020-7793
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196086
|
7.5 |
HIGH
Network
|
moutjs
|
mout
|
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing …
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7792
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196087
|
5.3 |
MEDIUM
Network
|
spatie
|
browsershot
|
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
|
CWE-22
Path Traversal
|
CVE-2020-7790
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196088
|
9.8 |
CRITICAL
Network
|
ini_project debian
|
ini debian_linux
|
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7788
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196089
|
5.6 |
MEDIUM
Network
|
node-notifier_project
|
node-notifier
|
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
|
CWE-78
OS Command
|
CVE-2020-7789
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196090
|
8.6 |
HIGH
Local
|
schneider-electric
|
unity_pro ecostruxure_control_expert
|
A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a …
|
-
|
CVE-2020-7560
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|