2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9708 | HIGH | 7.5 | 2.9% | Aug 14, 2020 | The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid G... |
| CVE-2020-15145 | HIGH | 8.2 | 0.4% | Aug 14, 2020 | In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local atta... |
| CVE-2020-15142 | CRITICAL | 9 | 1.6% | Aug 14, 2020 | In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generat... |
| CVE-2020-15141 | MEDIUM | 4.1 | 0.9% | Aug 14, 2020 | In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client usi... |
| CVE-2020-7583 | HIGH | 7.8 | 0.3% | Aug 14, 2020 | A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All ve... |
| CVE-2020-22722 | HIGH | 7.8 | 0.5% | Aug 14, 2020 | Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe ... |
| CVE-2020-22721 | HIGH | 7.8 | 0.5% | Aug 14, 2020 | A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary c... |
| CVE-2020-22720 | — | — | — | Aug 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-15781 | CRITICAL | 9.6 | 1.0% | Aug 14, 2020 | A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen... |
| CVE-2020-10055 | CRITICAL | 9.8 | 6.0% | Aug 14, 2020 | A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (... |
| CVE-2020-9229 | MEDIUM | 4.4 | 0.2% | Aug 14, 2020 | FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, ... |
| CVE-2020-9228 | HIGH | 7.5 | 0.8% | Aug 14, 2020 | FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, ... |
| CVE-2020-7701 | CRITICAL | 9.8 | 2.1% | Aug 14, 2020 | madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue. |
| CVE-2020-7700 | CRITICAL | 9.8 | 1.9% | Aug 14, 2020 | All versions of phpjs are vulnerable to Prototype Pollution via parse_str. |
| CVE-2020-17462 | HIGH | 7.8 | 1.0% | Aug 14, 2020 | CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a... |
| CVE-2020-16205 | HIGH | 7.2 | 60.4% | Aug 14, 2020 | Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code ... |
| CVE-2020-12648 | MEDIUM | 6.1 | 1.8% | Aug 14, 2020 | A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web ... |
| CVE-2020-4662 | HIGH | 8.8 | 1.3% | Aug 14, 2020 | IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication v... |
| CVE-2020-7360 | HIGH | 7.3 | 0.5% | Aug 13, 2020 | An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before ... |
| CVE-2020-24349 | MEDIUM | 5.5 | 0.5% | Aug 13, 2020 | njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor cons... |
| CVE-2020-24348 | MEDIUM | 5.5 | 0.4% | Aug 13, 2020 | njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c. |
| CVE-2020-24347 | MEDIUM | 5.5 | 0.4% | Aug 13, 2020 | njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c. |
| CVE-2020-24346 | HIGH | 7.8 | 1.0% | Aug 13, 2020 | njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c. |
| CVE-2020-24345 | HIGH | 7.8 | 0.8% | Aug 13, 2020 | JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the ve... |
| CVE-2020-24344 | HIGH | 7.1 | 0.8% | Aug 13, 2020 | JerryScript through 2.3.0 has a (function({a=arguments}){const arguments}) buffer over-read. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now