|
198671
|
8.2 |
HIGH
Network
|
phantomjs-seo_project
|
phantomjs-seo
|
This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowing for an SSRF attack.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-7739
|
2024-11-21 14:37 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198672
|
7.5 |
HIGH
Network
|
mpd_project stormshield
|
mpd stormshield_network_security
|
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7466
|
2024-11-21 14:37 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198673
|
9.8 |
CRITICAL
Network
|
mpd_project stormshield
|
mpd stormshield_network_security
|
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of servi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7465
|
2024-11-21 14:37 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198674
|
8.3 |
HIGH
Network
|
shiba_project
|
shiba
|
All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load() of the package js-yaml instead of its secure replacement , safeLoad().
|
NVD-CWE-noinfo
|
CVE-2020-7738
|
2024-11-21 14:37 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198675
|
9.8 |
CRITICAL
Network
|
safetydance_project
|
safetydance
|
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7737
|
2024-11-21 14:37 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198676
|
9.8 |
CRITICAL
Network
|
bmoor_project
|
bmoor
|
The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7736
|
2024-11-21 14:37 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198677
|
6.6 |
MEDIUM
Network
|
ng-packagr_project
|
ng-packagr
|
The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.
|
CWE-78
OS Command
|
CVE-2020-7735
|
2024-11-21 14:37 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198678
|
8.2 |
HIGH
Network
|
arachnys
|
cabot
|
All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7734
|
2024-11-21 14:37 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198679
|
6.5 |
MEDIUM
Local
|
rapid7
|
appspider
|
In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This wo…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-7358
|
2024-11-21 14:37 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198680
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_x70_security_administrator
|
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-7532
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|