CVE-2020-28441

This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This c ...

Continue Reading
CVE-2020-28443

This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.Read More ...

Continue Reading
CVE-2020-28438

This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.jsRead More ...

Continue Reading
CVE-2020-28435

This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.Read More ...

Continue Reading
CVE-2020-28422

All versions of package git-archive are vulnerable to Command Injection via the exports function.Read More ...

Continue Reading
CVE-2020-28436

This affects all versions of package google-cloudstorage-commands.Read More ...

Continue Reading
CVE-2022-21802

The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.Read More ...

Continue Reading
CVE-2022-2514

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: