|
209851
|
7.5 |
HIGH
Network
|
controlled-merge_project
|
controlled-merge
|
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-28268
|
2024-11-21 14:22 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209852
|
6.1 |
MEDIUM
Network
|
tranzware_payment_gateway_project
|
tranzware_payment_gateway
|
A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (diff…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28415
|
2024-11-21 14:22 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209853
|
6.1 |
MEDIUM
Network
|
tranzware_payment_gateway_project
|
tranzware_payment_gateway
|
A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (diff…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28414
|
2024-11-21 14:22 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209854
|
9.8 |
CRITICAL
Network
|
deephas_project
|
deephas
|
Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-28271
|
2024-11-21 14:22 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209855
|
9.8 |
CRITICAL
Network
|
mjpclab
|
object-hierarchy-access
|
Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-28270
|
2024-11-21 14:22 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209856
|
9.8 |
CRITICAL
Network
|
exodus
|
field
|
Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-28269
|
2024-11-21 14:22 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209857
|
5.3 |
MEDIUM
Network
|
lettre
|
lettre
|
The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.
|
NVD-CWE-noinfo
|
CVE-2020-28247
|
2024-11-21 14:22 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209858
|
5.4 |
MEDIUM
Network
|
dundas
|
dundas_bi
|
The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28409
|
2024-11-21 14:22 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209859
|
5.4 |
MEDIUM
Network
|
dundas
|
dundas_bi
|
The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28408
|
2024-11-21 14:22 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209860
|
4.4 |
MEDIUM
Local
|
xen fedoraproject debian
|
xen fedora debian_linux
|
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Pl…
|
CWE-862
Missing Authorization
|
CVE-2020-28368
|
2024-11-21 14:22 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|