Security Vulnerabilities
- CVEs Published In 2020
All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls.
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation of an HTTP request, where the content for the attack has been loaded into ePO by an ePO administrator.
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Windows Spoofing Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Microsoft Teams Remote Code Execution Vulnerability
Visual Studio Tampering Vulnerability