2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24583HIGH7.5An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used)....
CVE-2020-8023HIGH7.8A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enter...
CVE-2020-7727CRITICAL9.8All versions of package gedi are vulnerable to Prototype Pollution via the set function.
CVE-2020-7726CRITICAL9.8All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
CVE-2020-7725CRITICAL9.8All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.
CVE-2020-7724CRITICAL9.8All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
CVE-2020-7723CRITICAL9.8All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
CVE-2020-7722CRITICAL9.8All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
CVE-2020-7721CRITICAL9.8All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.
CVE-2020-7720HIGH7.3The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0...
CVE-2020-7719CRITICAL9.8Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
CVE-2020-7718CRITICAL9.8All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
CVE-2020-7717CRITICAL9.8All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
CVE-2020-7716CRITICAL9.8All versions of package deeps are vulnerable to Prototype Pollution via the set function.
CVE-2020-7715CRITICAL9.8All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
CVE-2020-7714CRITICAL9.8All versions of package confucious are vulnerable to Prototype Pollution via the set function.
CVE-2020-7713CRITICAL9.8All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
CVE-2020-12776HIGH7.2Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after...
CVE-2020-14178HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Infor...
CVE-2020-25067HIGH8.8NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
CVE-2020-15704MEDIUM5.5The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module load...
CVE-2020-25065HIGH7.5An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 softwar...
CVE-2020-25064HIGH7.5An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 softwar...
CVE-2020-25063HIGH7.5An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can...
CVE-2020-25062CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of i...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now