|
197041
|
9.8 |
CRITICAL
Network
|
json-ptr_project
|
json-ptr
|
This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true.…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7766
|
2024-11-21 14:37 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197042
|
7.5 |
HIGH
Network
|
find-my-way_project
|
find-my-way
|
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a deni…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-7764
|
2024-11-21 14:37 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197043
|
7.5 |
HIGH
Network
|
jsreport
|
phantom-html-to-pdf
|
This affects the package phantom-html-to-pdf before 0.6.1.
|
CWE-22
Path Traversal
|
CVE-2020-7763
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197044
|
6.5 |
MEDIUM
Network
|
jsreport
|
jsreport-chrome-pdf
|
This affects the package jsreport-chrome-pdf before 1.10.0.
|
CWE-22
Path Traversal
|
CVE-2020-7762
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197045
|
5.3 |
MEDIUM
Network
|
absolunet
|
kafe
|
This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails.
|
NVD-CWE-noinfo
|
CVE-2020-7761
|
2024-11-21 14:37 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197046
|
7.5 |
HIGH
Network
|
browserless
|
chrome
|
This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then s…
|
CWE-22
Path Traversal
|
CVE-2020-7758
|
2024-11-21 14:37 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197047
|
6.5 |
MEDIUM
Network
|
droppy_project
|
droppy
|
This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server.
|
CWE-22
Path Traversal
|
CVE-2020-7757
|
2024-11-21 14:37 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197048
|
9.8 |
CRITICAL
Network
|
vbulletin
|
vbulletin
|
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete …
|
CWE-94
Code Injection
|
CVE-2020-7373
|
2024-11-21 14:37 |
2020-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197049
|
7.5 |
HIGH
Network
|
codemirror oracle
|
codemirror application_express essbase enterprise_manager_express_user_interface hyperion_data_relationship_management spatial_studio
|
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/Code…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-7760
|
2024-11-21 14:37 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197050
|
7.2 |
HIGH
Network
|
pimcore
|
pimcore
|
The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a speci…
|
CWE-89
SQL Injection
|
CVE-2020-7759
|
2024-11-21 14:37 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|