2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7754 | HIGH | 7.5 | 3.4% | Oct 27, 2020 | This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer ... |
| CVE-2020-23945 | HIGH | 7.5 | 1.2% | Oct 27, 2020 | A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter... |
| CVE-2020-8579 | HIGH | 7.5 | 1.3% | Oct 27, 2020 | Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access ... |
| CVE-2020-6023 | HIGH | 7.8 | 0.3% | Oct 27, 2020 | Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in... |
| CVE-2020-6022 | MEDIUM | 5.5 | 0.3% | Oct 27, 2020 | Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files... |
| CVE-2020-23864 | HIGH | 7.8 | 0.5% | Oct 27, 2020 | An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a mali... |
| CVE-2020-10256 | CRITICAL | 9.8 | 0.9% | Oct 27, 2020 | An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1... |
| CVE-2020-7753 | HIGH | 7.5 | 3.7% | Oct 27, 2020 | All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim(). |
| CVE-2020-8956 | LOW | 3.3 | 1.2% | Oct 27, 2020 | Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settin... |
| CVE-2020-27183 | CRITICAL | 9.8 | 1.3% | Oct 27, 2020 | A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to discl... |
| CVE-2020-27182 | MEDIUM | 6.1 | 0.8% | Oct 27, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to in... |
| CVE-2020-27181 | MEDIUM | 6.5 | 0.9% | Oct 27, 2020 | A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to c... |
| CVE-2020-27180 | HIGH | 7.5 | 1.2% | Oct 27, 2020 | konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter. |
| CVE-2020-27179 | CRITICAL | 9.8 | 1.3% | Oct 27, 2020 | konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset to... |
| CVE-2020-15352 | HIGH | 7.2 | 3.2% | Oct 27, 2020 | An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) befo... |
| CVE-2020-27743 | CRITICAL | 9.8 | 1.7% | Oct 26, 2020 | libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to ... |
| CVE-2020-1915 | HIGH | 7.5 | 1.6% | Oct 26, 2020 | An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c7... |
| CVE-2020-26879 | CRITICAL | 9.8 | 42.5% | Oct 26, 2020 | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacke... |
| CVE-2020-26878 | HIGH | 8.8 | 11.5% | Oct 26, 2020 | Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (... |
| CVE-2020-25034 | MEDIUM | 6.5 | 1.4% | Oct 26, 2020 | eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via th... |
| CVE-2020-15274 | MEDIUM | 5.4 | 0.8% | Oct 26, 2020 | In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. W... |
| CVE-2020-15272 | CRITICAL | 9.6 | 1.2% | Oct 26, 2020 | In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*)... |
| CVE-2020-26566 | HIGH | 7.5 | 4.4% | Oct 26, 2020 | A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a ... |
| CVE-2020-26161 | MEDIUM | 6.1 | 1.1% | Oct 26, 2020 | In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header... |
| CVE-2020-15271 | HIGH | 8.8 | 2.0% | Oct 26, 2020 | In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now