2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24583 | HIGH | 7.5 | 4.0% | Sep 1, 2020 | An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used).... |
| CVE-2020-8023 | HIGH | 7.8 | 0.4% | Sep 1, 2020 | A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enter... |
| CVE-2020-7727 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package gedi are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7726 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function. |
| CVE-2020-7725 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function. |
| CVE-2020-7724 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7723 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function. |
| CVE-2020-7722 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function. |
| CVE-2020-7721 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function. |
| CVE-2020-7720 | HIGH | 7.3 | 3.2% | Sep 1, 2020 | The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0... |
| CVE-2020-7719 | CRITICAL | 9.8 | 2.8% | Sep 1, 2020 | Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function. |
| CVE-2020-7718 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions. |
| CVE-2020-7717 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package dot-notes are vulnerable to Prototype Pollution via the create function. |
| CVE-2020-7716 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package deeps are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7715 | CRITICAL | 9.8 | 2.0% | Sep 1, 2020 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function. |
| CVE-2020-7714 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package confucious are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7713 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor. |
| CVE-2020-12776 | HIGH | 7.2 | 0.8% | Sep 1, 2020 | Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after... |
| CVE-2020-14178 | HIGH | 7.5 | 3.1% | Sep 1, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Infor... |
| CVE-2020-25067 | HIGH | 8.8 | 2.0% | Sep 1, 2020 | NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker. |
| CVE-2020-15704 | MEDIUM | 5.5 | 0.4% | Sep 1, 2020 | The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module load... |
| CVE-2020-25065 | HIGH | 7.5 | 0.5% | Aug 31, 2020 | An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 softwar... |
| CVE-2020-25064 | HIGH | 7.5 | 0.3% | Aug 31, 2020 | An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 softwar... |
| CVE-2020-25063 | HIGH | 7.5 | 0.4% | Aug 31, 2020 | An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can... |
| CVE-2020-25062 | CRITICAL | 9.8 | 0.5% | Aug 31, 2020 | An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of i... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now