2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28461 | CRITICAL | 9.8 | 1.0% | Jul 25, 2022 | This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses ... |
| CVE-2020-28447 | CRITICAL | 9.8 | 1.1% | Jul 25, 2022 | This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported functi... |
| CVE-2020-28446 | CRITICAL | 9.8 | 3.3% | Jul 25, 2022 | The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. |
| CVE-2020-28445 | CRITICAL | 9.8 | 1.2% | Jul 25, 2022 | This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.late... |
| CVE-2020-28443 | CRITICAL | 9.8 | 1.1% | Jul 25, 2022 | This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js. |
| CVE-2020-28441 | CRITICAL | 9.8 | 1.0% | Jul 25, 2022 | This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that p... |
| CVE-2020-28438 | CRITICAL | 9.8 | 1.1% | Jul 25, 2022 | This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js |
| CVE-2020-28436 | CRITICAL | 9.8 | 0.8% | Jul 25, 2022 | This affects all versions of package google-cloudstorage-commands. |
| CVE-2020-28435 | CRITICAL | 9.8 | 1.1% | Jul 25, 2022 | This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js. |
| CVE-2020-35169 | CRITICAL | 9.8 | 0.9% | Jul 11, 2022 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, con... |
| CVE-2020-35168 | CRITICAL | 9.8 | 0.4% | Jul 11, 2022 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, conta... |
| CVE-2020-35167 | CRITICAL | 9.8 | 0.9% | Jul 11, 2022 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, conta... |
| CVE-2020-35166 | CRITICAL | 9.8 | 0.6% | Jul 11, 2022 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, conta... |
| CVE-2020-35163 | CRITICAL | 9.8 | 0.9% | Jul 11, 2022 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, conta... |
| CVE-2020-29508 | CRITICAL | 9.8 | 1.0% | Jul 11, 2022 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, conta... |
| CVE-2020-29507 | CRITICAL | 9.8 | 0.9% | Jul 11, 2022 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, conta... |
| CVE-2020-29506 | CRITICAL | 9.8 | 1.0% | Jul 11, 2022 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, con... |
| CVE-2020-4150 | CRITICAL | 9.8 | 0.8% | Jul 11, 2022 | IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it use... |
| CVE-2020-19896 | CRITICAL | 9.8 | 1.5% | Jun 28, 2022 | File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php. |
| CVE-2020-36542 | CRITICAL | 9.8 | 1.3% | Jun 7, 2022 | A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/i... |
| CVE-2020-36541 | CRITICAL | 9.8 | 1.2% | Jun 7, 2022 | A vulnerability was found in Demokratian. It has been rated as critical. Affected by this issue is some unknown function... |
| CVE-2020-36540 | CRITICAL | 9.8 | 0.6% | Jun 7, 2022 | A vulnerability, which was classified as critical, was found in Neetai Tech. Affected is an unknown function of the file... |
| CVE-2020-36539 | CRITICAL | 9.8 | 0.6% | Jun 7, 2022 | A vulnerability was found in Lógico y Creativo 1.0 and classified as critical. This issue affects some unknown processin... |
| CVE-2020-36533 | CRITICAL | 9.8 | 1.4% | Jun 7, 2022 | A vulnerability was found in Klapp App and classified as problematic. This issue affects some unknown processing of the ... |
| CVE-2020-28246 | CRITICAL | 9.8 | 2.2% | Jun 2, 2022 | A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during dele... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now