2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28439CRITICAL9.8This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depe...
CVE-2020-27134CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-27133CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-27132CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-27127CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-26265MEDIUM5.3Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and b...
CVE-2020-26264MEDIUM6.5Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a ...
CVE-2020-35144Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-29589Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation du...
CVE-2020-29254HIGH8.8TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacke...
CVE-2020-27508HIGH7.5In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach th...
CVE-2020-15357CRITICAL9.8Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to exec...
CVE-2020-15023MEDIUM5.9Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arise...
CVE-2020-12149MEDIUM6.8The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly in...
CVE-2020-12148MEDIUM6.8A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allo...
CVE-2020-4633HIGH8.8IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula inject...
CVE-2020-29591CRITICAL9.8Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deploy...
CVE-2020-29590Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation du...
CVE-2020-28838LOW3.5Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items...
CVE-2020-7793HIGH7.5The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexe...
CVE-2020-17515MEDIUM6.1The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects...
CVE-2020-7792HIGH7.5This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively',...
CVE-2020-7790MEDIUM5.3This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able ...
CVE-2020-7788CRITICAL9.8This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it ...
CVE-2020-7789MEDIUM5.6This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines d...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now