2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-8147CRITICAL9.8Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that...
CVE-2020-8638CRITICAL9.8A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php v...
CVE-2020-8637CRITICAL9.8A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes...
CVE-2020-6994CRITICAL9.8A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vul...
CVE-2020-10599CRITICAL9.8VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited...
CVE-2020-7630CRITICAL9.8git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name ...
CVE-2020-7629CRITICAL9.8install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the opti...
CVE-2020-7628CRITICAL9.8umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sani...
CVE-2020-7627CRITICAL9.8node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'ar...
CVE-2020-7626CRITICAL9.8karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config ar...
CVE-2020-7625CRITICAL9.8op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url funct...
CVE-2020-7624CRITICAL9.8effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argume...
CVE-2020-10515CRITICAL9.8STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-...
CVE-2020-7623CRITICAL9.8jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argume...
CVE-2020-7621CRITICAL9.8strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as pa...
CVE-2020-7620CRITICAL9.8pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'po...
CVE-2020-7619CRITICAL9.8get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of th...
CVE-2020-7617CRITICAL9.8ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying prop...
CVE-2020-6852CRITICAL9.8CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access,...
CVE-2020-6009CRITICAL9.8LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
CVE-2020-10948CRITICAL9.8Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution v...
CVE-2020-3850CRITICAL9.8A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A...
CVE-2020-3849CRITICAL9.8A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A...
CVE-2020-3848CRITICAL9.8A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A...
CVE-2020-3847CRITICAL9.8An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A rem...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now