Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 32233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28478 1 Greensock 1 Greensock Animation Platform 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects the package gsap before 3.6.0.
CVE-2020-28477 1 Immer Project 1 Immer 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package immer.
CVE-2020-28472 1 Amazon 2 Aws Sdk For Javascipt, Aws Shared Configuration File Loader 2024-11-21 7.5 HIGH 7.3 HIGH
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.
CVE-2020-28466 1 Nats 1 Nats Server 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened risk. Any remote execution flaw or equivalent seriousness, or denial-of-service by unauthenticated users, will lead to prompt releases by the NATS maintainers. Fixes for denial of service issues with no threat of remote execution, when limited to account holders, are likely to just be committed to the main development branch with no special attention. Those who are running such services are encouraged to build regularly from git.
CVE-2020-28421 2 Broadcom, Microsoft 2 Unified Infrastructure Management, Windows 2024-11-21 4.6 MEDIUM 7.8 HIGH
CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that allows local attackers to elevate privileges.
CVE-2020-28419 1 Hp 1503 Laserjet Managed Mfp E62665 3gy14a, Laserjet Managed Mfp E62665 3gy15a, Laserjet Managed Mfp E62665 3gy16a and 1500 more 2024-11-21 6.8 MEDIUM 8.8 HIGH
During installation with certain driver software or application packages an arbitrary code execution could occur.
CVE-2020-28416 1 Hp 310 Officejet 250 Cz992a, Officejet 250 Cz992a Firmware, Officejet 250c L9d57a and 307 more 2024-11-21 4.6 MEDIUM 7.8 HIGH
HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.
CVE-2020-28340 1 Google 1 Android 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020-18546 (November 2020).
CVE-2020-28281 1 Set-object-value Project 1 Set-object-value 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28280 1 Predefine Project 1 Predefine 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28279 1 Flattenizer Project 1 Flattenizer 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28278 1 Shvl Project 1 Shvl 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28277 1 Dset Project 1 Dset 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28276 1 Deep-set Project 1 Deep-set 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28274 1 Deepref Project 1 Deepref 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28273 1 Set-in Project 1 Set-in 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28272 1 Keyget Project 1 Keyget 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28267 1 Set Project 1 Set 2024-11-21 5.0 MEDIUM 7.5 HIGH
Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28251 1 Netscout 7 Airmagnet Enterprise, Sensor4-r1s1w1-e, Sensor4-r2s1-e and 4 more 2024-11-21 9.3 HIGH 8.1 HIGH
NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward password-cracking exercise.
CVE-2020-28247 1 Lettre 1 Lettre 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.