2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9708HIGH7.5The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid G...
CVE-2020-15145HIGH8.2In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local atta...
CVE-2020-15142CRITICAL9In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generat...
CVE-2020-15141MEDIUM4.1In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client usi...
CVE-2020-7583HIGH7.8A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All ve...
CVE-2020-22722HIGH7.8Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe ...
CVE-2020-22721HIGH7.8A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary c...
CVE-2020-22720Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-15781CRITICAL9.6A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen...
CVE-2020-10055CRITICAL9.8A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (...
CVE-2020-9229MEDIUM4.4FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, ...
CVE-2020-9228HIGH7.5FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, ...
CVE-2020-7701CRITICAL9.8madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
CVE-2020-7700CRITICAL9.8All versions of phpjs are vulnerable to Prototype Pollution via parse_str.
CVE-2020-17462HIGH7.8CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a...
CVE-2020-16205HIGH7.2Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code ...
CVE-2020-12648MEDIUM6.1A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web ...
CVE-2020-4662HIGH8.8IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication v...
CVE-2020-7360HIGH7.3An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before ...
CVE-2020-24349MEDIUM5.5njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor cons...
CVE-2020-24348MEDIUM5.5njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
CVE-2020-24347MEDIUM5.5njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c.
CVE-2020-24346HIGH7.8njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.
CVE-2020-24345HIGH7.8JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the ve...
CVE-2020-24344HIGH7.1JerryScript through 2.3.0 has a (function({a=arguments}){const arguments}) buffer over-read.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now