This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This c ...
Continue ReadingJuly 25, 2022
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.Read More ...
Continue ReadingJuly 25, 2022
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.jsRead More ...
Continue ReadingJuly 25, 2022
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.Read More ...
Continue ReadingJuly 25, 2022
All versions of package git-archive are vulnerable to Command Injection via the exports function.Read More ...
Continue ReadingJuly 25, 2022
This affects all versions of package google-cloudstorage-commands.Read More ...
Continue ReadingJuly 25, 2022
The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.Read More ...
Continue ReadingJuly 25, 2022
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.Read More ...
Continue ReadingJuly 25, 2022
Back to Main