2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28439 | CRITICAL | 9.8 | 1.6% | Dec 11, 2020 | This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depe... |
| CVE-2020-27134 | CRITICAL | 9.9 | 1.6% | Dec 11, 2020 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a... |
| CVE-2020-27133 | CRITICAL | 9.9 | 1.1% | Dec 11, 2020 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a... |
| CVE-2020-27132 | CRITICAL | 9.9 | 1.4% | Dec 11, 2020 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a... |
| CVE-2020-27127 | CRITICAL | 9.9 | 1.3% | Dec 11, 2020 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a... |
| CVE-2020-26265 | MEDIUM | 5.3 | 0.9% | Dec 11, 2020 | Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and b... |
| CVE-2020-26264 | MEDIUM | 6.5 | 1.9% | Dec 11, 2020 | Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a ... |
| CVE-2020-35144 | — | — | — | Dec 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-29589 | — | — | — | Dec 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation du... |
| CVE-2020-29254 | HIGH | 8.8 | 1.5% | Dec 11, 2020 | TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacke... |
| CVE-2020-27508 | HIGH | 7.5 | 1.3% | Dec 11, 2020 | In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach th... |
| CVE-2020-15357 | CRITICAL | 9.8 | 4.2% | Dec 11, 2020 | Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to exec... |
| CVE-2020-15023 | MEDIUM | 5.9 | 1.6% | Dec 11, 2020 | Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arise... |
| CVE-2020-12149 | MEDIUM | 6.8 | 1.3% | Dec 11, 2020 | The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly in... |
| CVE-2020-12148 | MEDIUM | 6.8 | 2.1% | Dec 11, 2020 | A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allo... |
| CVE-2020-4633 | HIGH | 8.8 | 2.7% | Dec 11, 2020 | IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula inject... |
| CVE-2020-29591 | CRITICAL | 9.8 | 2.6% | Dec 11, 2020 | Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deploy... |
| CVE-2020-29590 | — | — | — | Dec 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation du... |
| CVE-2020-28838 | LOW | 3.5 | 0.4% | Dec 11, 2020 | Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items... |
| CVE-2020-7793 | HIGH | 7.5 | 3.9% | Dec 11, 2020 | The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexe... |
| CVE-2020-17515 | MEDIUM | 6.1 | 16.0% | Dec 11, 2020 | The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects... |
| CVE-2020-7792 | HIGH | 7.5 | 2.1% | Dec 11, 2020 | This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively',... |
| CVE-2020-7790 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able ... |
| CVE-2020-7788 | CRITICAL | 9.8 | 3.6% | Dec 11, 2020 | This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it ... |
| CVE-2020-7789 | MEDIUM | 5.6 | 1.6% | Dec 11, 2020 | This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines d... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now