2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6998HIGH8.6The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 ...
CVE-2020-36290MEDIUM5.4The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and fro...
CVE-2020-7678CRITICAL9.8This affects all versions of package node-import. The "params" argument of module function can be controlled by users wi...
CVE-2020-7677CRITICAL9.8This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users with...
CVE-2020-7649MEDIUM4.9This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's inter...
CVE-2020-28471CRITICAL9.8This affects the package properties-reader before 2.2.0.
CVE-2020-28462CRITICAL9.8This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that pars...
CVE-2020-28461CRITICAL9.8This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses ...
CVE-2020-28459MEDIUM6.1This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx fo...
CVE-2020-28455MEDIUM6.1This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are ...
CVE-2020-28447CRITICAL9.8This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported functi...
CVE-2020-28446CRITICAL9.8The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
CVE-2020-28445CRITICAL9.8This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.late...
CVE-2020-28443CRITICAL9.8This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
CVE-2020-28441CRITICAL9.8This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that p...
CVE-2020-28438CRITICAL9.8This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js
CVE-2020-28436CRITICAL9.8This affects all versions of package google-cloudstorage-commands.
CVE-2020-28435CRITICAL9.8This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
CVE-2020-28422HIGH7.8All versions of package git-archive are vulnerable to Command Injection via the exports function.
CVE-2020-14126HIGH7.5Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sens...
CVE-2020-14114HIGH7.5information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of s...
CVE-2020-36558MEDIUM5.1A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and gene...
CVE-2020-36557MEDIUM5.1A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lea...
CVE-2020-21406HIGH7.5An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service vi...
CVE-2020-21405HIGH7.5An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now