2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7603 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports fun... |
| CVE-2020-7602 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" fu... |
| CVE-2020-7601 | CRITICAL | 9.8 | 2.6% | Mar 15, 2020 | gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the ... |
| CVE-2020-10594 | CRITICAL | 9.1 | 1.3% | Mar 15, 2020 | An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated tok... |
| CVE-2020-0086 | CRITICAL | 9.8 | 0.6% | Mar 15, 2020 | In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to arb... |
| CVE-2020-10574 | CRITICAL | 9.8 | 1.2% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "quer... |
| CVE-2020-10571 | CRITICAL | 9.8 | 1.7% | Mar 14, 2020 | An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious... |
| CVE-2020-10567 | CRITICAL | 9.8 | 19.3% | Mar 14, 2020 | An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in t... |
| CVE-2020-10564 | CRITICAL | 9.8 | 8.6% | Mar 13, 2020 | An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote ... |
| CVE-2020-10563 | CRITICAL | 9.8 | 1.7% | Mar 13, 2020 | An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query. |
| CVE-2020-10077 | CRITICAL | 9.8 | 1.2% | Mar 13, 2020 | GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was cr... |
| CVE-2020-10074 | CRITICAL | 9.8 | 1.3% | Mar 13, 2020 | GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be ta... |
| CVE-2020-10083 | CRITICAL | 9.1 | 1.1% | Mar 13, 2020 | GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization ch... |
| CVE-2020-1953 | CRITICAL | 10 | 6.7% | Mar 13, 2020 | Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of... |
| CVE-2020-10541 | CRITICAL | 9.8 | 10.1% | Mar 13, 2020 | Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1... |
| CVE-2020-1887 | CRITICAL | 9.1 | 1.3% | Mar 13, 2020 | Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to... |
| CVE-2020-10534 | CRITICAL | 9.8 | 1.2% | Mar 12, 2020 | In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation ... |
| CVE-2020-0902 | CRITICAL | 9.8 | 2.9% | Mar 12, 2020 | An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Servi... |
| CVE-2020-0872 | CRITICAL | 9.6 | 9.9% | Mar 12, 2020 | A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects ... |
| CVE-2020-0796 | CRITICAL | 10 | 99.8% | Mar 12, 2020 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h... |
| CVE-2020-0690 | CRITICAL | 9.8 | 6.8% | Mar 12, 2020 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation... |
| CVE-2020-10109 | CRITICAL | 9.8 | 3.3% | Mar 12, 2020 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length ... |
| CVE-2020-10108 | CRITICAL | 9.8 | 4.1% | Mar 12, 2020 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-lengt... |
| CVE-2020-1947 | CRITICAL | 9.8 | 33.9% | Mar 11, 2020 | In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for... |
| CVE-2020-8540 | CRITICAL | 9.8 | 12.5% | Mar 11, 2020 | An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows rem... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now