Search Results (328890 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-7655 1 Hive 1 Netius 2024-11-21 6.1 Medium
netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Transfer encoding header parsing which could allow for CL:TE or TE:TE attacks.
CVE-2020-7654 1 Synk 1 Broker 2024-11-21 7.5 High
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.
CVE-2020-7653 1 Synk 1 Broker 2024-11-21 6.5 Medium
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.
CVE-2020-7652 1 Synk 1 Broker 2024-11-21 6.5 Medium
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
CVE-2020-7651 1 Synk 1 Broker 2024-11-21 4.3 Medium
All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.
CVE-2020-7650 1 Synk 1 Broker 2024-11-21 6.5 Medium
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
CVE-2020-7649 1 Snyk 1 Broker 2024-11-21 4.9 Medium
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
CVE-2020-7648 1 Synk 1 Broker 2024-11-21 6.5 Medium
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. `#package.json`
CVE-2020-7647 1 Jooby 1 Jooby 2024-11-21 5.3 Medium
All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal via two separate vectors.
CVE-2020-7646 1 Curlrequest Project 1 Curlrequest 2024-11-21 9.8 Critical
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
CVE-2020-7645 1 Google 1 Chrome-launcher 2024-11-21 9.8 Critical
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.
CVE-2020-7644 1 Fun-map Project 1 Fun-map 2024-11-21 8.1 High
fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
CVE-2020-7643 1 Idea 1 Paypal-adaptive 2024-11-21 5.3 Medium
paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
CVE-2020-7642 1 Lazysizes Project 1 Lazysizes 2024-11-21 5.4 Medium
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.
CVE-2020-7641 1 Grunt-util-property Project 1 Grunt-util-property 2024-11-21 4 Medium
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
CVE-2020-7640 1 Pixlcore 1 Pixl-class 2024-11-21 9.8 Critical
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
CVE-2020-7639 1 Dot Project 1 Dot 2024-11-21 5.3 Medium
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
CVE-2020-7638 1 Confinit Project 1 Confinit 2024-11-21 5.3 Medium
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
CVE-2020-7637 1 Class-transformer Project 1 Class-transformer 2024-11-21 5.3 Medium
class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
CVE-2020-7636 1 Adb-driver Project 1 Adb-driver 2024-11-21 9.8 Critical
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.