2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8147 | CRITICAL | 9.8 | 3.1% | Apr 3, 2020 | Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that... |
| CVE-2020-8638 | CRITICAL | 9.8 | 1.7% | Apr 3, 2020 | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php v... |
| CVE-2020-8637 | CRITICAL | 9.8 | 2.9% | Apr 3, 2020 | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes... |
| CVE-2020-6994 | CRITICAL | 9.8 | 1.6% | Apr 3, 2020 | A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vul... |
| CVE-2020-10599 | CRITICAL | 9.8 | 2.5% | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited... |
| CVE-2020-7630 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name ... |
| CVE-2020-7629 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the opti... |
| CVE-2020-7628 | CRITICAL | 9.8 | 1.7% | Apr 2, 2020 | umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sani... |
| CVE-2020-7627 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'ar... |
| CVE-2020-7626 | CRITICAL | 9.8 | 4.2% | Apr 2, 2020 | karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config ar... |
| CVE-2020-7625 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url funct... |
| CVE-2020-7624 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argume... |
| CVE-2020-10515 | CRITICAL | 9.8 | 2.9% | Apr 2, 2020 | STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-... |
| CVE-2020-7623 | CRITICAL | 9.8 | 3.5% | Apr 2, 2020 | jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argume... |
| CVE-2020-7621 | CRITICAL | 9.8 | 2.9% | Apr 2, 2020 | strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as pa... |
| CVE-2020-7620 | CRITICAL | 9.8 | 2.1% | Apr 2, 2020 | pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'po... |
| CVE-2020-7619 | CRITICAL | 9.8 | 2.1% | Apr 2, 2020 | get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of th... |
| CVE-2020-7617 | CRITICAL | 9.8 | 0.9% | Apr 2, 2020 | ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying prop... |
| CVE-2020-6852 | CRITICAL | 9.8 | 2.4% | Apr 2, 2020 | CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access,... |
| CVE-2020-6009 | CRITICAL | 9.8 | 1.8% | Apr 1, 2020 | LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. |
| CVE-2020-10948 | CRITICAL | 9.8 | 6.7% | Apr 1, 2020 | Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution v... |
| CVE-2020-3850 | CRITICAL | 9.8 | 3.2% | Apr 1, 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A... |
| CVE-2020-3849 | CRITICAL | 9.8 | 2.2% | Apr 1, 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A... |
| CVE-2020-3848 | CRITICAL | 9.8 | 2.2% | Apr 1, 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A... |
| CVE-2020-3847 | CRITICAL | 9.8 | 2.2% | Apr 1, 2020 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A rem... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now