2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7754HIGH7.5This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer ...
CVE-2020-23945HIGH7.5A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter...
CVE-2020-8579HIGH7.5Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access ...
CVE-2020-6023HIGH7.8Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in...
CVE-2020-6022MEDIUM5.5Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files...
CVE-2020-23864HIGH7.8An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a mali...
CVE-2020-10256CRITICAL9.8An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1...
CVE-2020-7753HIGH7.5All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
CVE-2020-8956LOW3.3Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settin...
CVE-2020-27183CRITICAL9.8A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to discl...
CVE-2020-27182MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to in...
CVE-2020-27181MEDIUM6.5A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to c...
CVE-2020-27180HIGH7.5konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
CVE-2020-27179CRITICAL9.8konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset to...
CVE-2020-15352HIGH7.2An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) befo...
CVE-2020-27743CRITICAL9.8libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to ...
CVE-2020-1915HIGH7.5An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c7...
CVE-2020-26879CRITICAL9.8Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacke...
CVE-2020-26878HIGH8.8Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (...
CVE-2020-25034MEDIUM6.5eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via th...
CVE-2020-15274MEDIUM5.4In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. W...
CVE-2020-15272CRITICAL9.6In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*)...
CVE-2020-26566HIGH7.5A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a ...
CVE-2020-26161MEDIUM6.1In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header...
CVE-2020-15271HIGH8.8In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now