Search Results (84168 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-7690 1 Parall 1 Jspdf 2024-11-21 6.1 Medium
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.
CVE-2020-7688 1 Mversion Project 1 Mversion 2024-11-21 8.4 High
The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
CVE-2020-7680 1 Docsifyjs 1 Docsify 2024-11-21 6.1 Medium
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.
CVE-2020-7677 3 Debian, Fedoraproject, Thenify Project 3 Debian Linux, Fedora, Thenify 2024-11-21 8.6 High
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
CVE-2020-7656 5 Jquery, Juniper, Netapp and 2 more 9 Jquery, Junos, Active Iq Unified Manager and 6 more 2024-11-21 6.1 Medium
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
CVE-2020-7646 1 Curlrequest Project 1 Curlrequest 2024-11-21 9.8 Critical
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
CVE-2020-7645 1 Google 1 Chrome-launcher 2024-11-21 9.8 Critical
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.
CVE-2020-7642 1 Lazysizes Project 1 Lazysizes 2024-11-21 5.4 Medium
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.
CVE-2020-7640 1 Pixlcore 1 Pixl-class 2024-11-21 9.8 Critical
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
CVE-2020-7636 1 Adb-driver Project 1 Adb-driver 2024-11-21 9.8 Critical
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.
CVE-2020-7635 1 Compass-compile Project 1 Compass-compile 2024-11-21 9.8 Critical
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
CVE-2020-7634 1 Heroku-addonpool Project 1 Heroku-addonpool 2024-11-21 9.8 Critical
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
CVE-2020-7633 1 Apiconnect-cli-plugins Project 1 Apiconnect-cli-plugins 2024-11-21 9.8 Critical
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
CVE-2020-7632 1 Node-mpv Project 1 Node-mpv 2024-11-21 9.8 Critical
node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
CVE-2020-7631 1 Diskusage-ng Project 1 Diskusage-ng 2024-11-21 9.8 Critical
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
CVE-2020-7630 1 Git-add-remote Project 1 Git-add-remote 2024-11-21 9.8 Critical
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
CVE-2020-7629 1 Install-package Project 1 Install-package 2024-11-21 9.8 Critical
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
CVE-2020-7628 2 Install-package Project, Umount Project 2 Install-package, Umount 2024-11-21 9.8 Critical
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
CVE-2020-7627 1 Node-key-sender Project 1 Node-key-sender 2024-11-21 9.8 Critical
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
CVE-2020-7626 1 Karma-mojo Project 1 Karma-mojo 2024-11-21 9.8 Critical
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.