|
196261
|
8.1 |
HIGH
Network
|
schneider-electric
|
modicon_tsxety4103_firmware modicon_tsxety5103_firmware modicon_tsxp574634_firmware modicon_tsxp575634_firmware modicon_tsxp576634_firmware modicon_quantum_140noe77101_firmware modi…
|
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) …
|
-
|
CVE-2020-7562
|
2024-11-21 14:37 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196262
|
8.8 |
HIGH
Network
|
tobesoft
|
xplatform
|
Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://
|
CWE-20
Improper Input Validation
|
CVE-2020-7841
|
2024-11-21 14:37 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196263
|
9.8 |
CRITICAL
Network
|
y18n_project oracle siemens
|
y18n graalvm sinec_infrastructure_network_services
|
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7774
|
2024-11-21 14:37 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196264
|
6.1 |
MEDIUM
Network
|
markdown-it-highlightjs_project
|
markdown-it-highlightjs
|
This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const mar…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7773
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196265
|
5.3 |
MEDIUM
Network
|
google
|
firebase\/util
|
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwr…
|
NVD-CWE-noinfo
|
CVE-2020-7765
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196266
|
9.8 |
CRITICAL
Network
|
doc-path_project
|
doc-path
|
This affects the package doc-path before 2.1.2.
|
NVD-CWE-noinfo
|
CVE-2020-7772
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196267
|
9.8 |
CRITICAL
Network
|
sugarcrm
|
sugarcrm
|
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenti…
|
CWE-94 CWE-20
Code Injection Improper Input Validation
|
CVE-2020-7472
|
2024-11-21 14:37 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196268
|
9.8 |
CRITICAL
Network
|
json8_project
|
json8
|
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype po…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7770
|
2024-11-21 14:37 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196269
|
4.8 |
MEDIUM
Network
|
mcafee
|
endpoint_security
|
Cross site scripting vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows administrators to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7333
|
2024-11-21 14:37 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196270
|
8.8 |
HIGH
Network
|
mcafee
|
endpoint_security
|
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to …
|
CWE-352
Origin Validation Error
|
CVE-2020-7332
|
2024-11-21 14:37 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|