Vendor
Install Package Project
Products
1
CVEs
2
Across products
2
Status
Private
Products
1- 2 CVEs
Recent CVEs
2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7629 | Cri | 0.64 | 9.8 | 0.04 | Apr 2, 2020 | install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. | ||
| CVE-2020-7628 | Cri | 0.64 | 9.8 | 0.02 | Apr 2, 2020 | umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization. |
- risk 0.64cvss 9.8epss 0.04
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
- risk 0.64cvss 9.8epss 0.02
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.