2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-7603CRITICAL9.8closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports fun...
CVE-2020-7602CRITICAL9.8node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" fu...
CVE-2020-7601CRITICAL9.8gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the ...
CVE-2020-10594CRITICAL9.1An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated tok...
CVE-2020-0086CRITICAL9.8In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to arb...
CVE-2020-10574CRITICAL9.8An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "quer...
CVE-2020-10571CRITICAL9.8An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious...
CVE-2020-10567CRITICAL9.8An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in t...
CVE-2020-10564CRITICAL9.8An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote ...
CVE-2020-10563CRITICAL9.8An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query.
CVE-2020-10077CRITICAL9.8GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was cr...
CVE-2020-10074CRITICAL9.8GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be ta...
CVE-2020-10083CRITICAL9.1GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization ch...
CVE-2020-1953CRITICAL10Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of...
CVE-2020-10541CRITICAL9.8Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1...
CVE-2020-1887CRITICAL9.1Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to...
CVE-2020-10534CRITICAL9.8In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation ...
CVE-2020-0902CRITICAL9.8An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Servi...
CVE-2020-0872CRITICAL9.6A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects ...
CVE-2020-0796CRITICAL10A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h...
CVE-2020-0690CRITICAL9.8An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation...
CVE-2020-10109CRITICAL9.8In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length ...
CVE-2020-10108CRITICAL9.8In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-lengt...
CVE-2020-1947CRITICAL9.8In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for...
CVE-2020-8540CRITICAL9.8An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows rem...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now