Show filters
267 Total Results
Displaying 171-180 of 267
Sort by:
Attacker Value
Unknown

CVE-2020-28450

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
This affects all versions of package decal. The vulnerability is in the extend function.
0
Attacker Value
Unknown

CVE-2020-28449

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
This affects all versions of package decal. The vulnerability is in the set function.
0
Attacker Value
Unknown

CVE-2020-22277

Disclosure Date: November 04, 2020 (last updated February 22, 2025)
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
Attacker Value
Unknown

CVE-2020-27533

Disclosure Date: October 22, 2020 (last updated February 22, 2025)
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
Attacker Value
Unknown

CVE-2018-17145

Disclosure Date: September 10, 2020 (last updated February 22, 2025)
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
Attacker Value
Unknown

CVE-2020-24074

Disclosure Date: September 09, 2020 (last updated February 22, 2025)
The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow.
Attacker Value
Unknown

CVE-2020-15123

Disclosure Date: July 20, 2020 (last updated February 21, 2025)
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. A similar CVE (CVE-2020-7597 for GHSA-5q88-cjfq-g2mh) was issued but the fix was incomplete. It only blocked &, and command injection is still possible using backticks instead to bypass the sanitizer. The attack surface is low in this case. Particularly in the standard use of codecov, where the module is used directly in a build pipeline, not built against as a library in another application that may supply malicious input and perform command injection.
Attacker Value
Unknown

CVE-2020-12265

Disclosure Date: April 26, 2020 (last updated February 21, 2025)
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.
Attacker Value
Unknown

CVE-2020-7597

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596.
Attacker Value
Unknown

CVE-2020-7596

Disclosure Date: January 25, 2020 (last updated February 21, 2025)
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.