2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-15150CRITICAL9.8There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) att...
CVE-2020-7727CRITICAL9.8All versions of package gedi are vulnerable to Prototype Pollution via the set function.
CVE-2020-7726CRITICAL9.8All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
CVE-2020-7725CRITICAL9.8All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.
CVE-2020-7724CRITICAL9.8All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
CVE-2020-7723CRITICAL9.8All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
CVE-2020-7722CRITICAL9.8All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
CVE-2020-7721CRITICAL9.8All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.
CVE-2020-7719CRITICAL9.8Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
CVE-2020-7718CRITICAL9.8All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
CVE-2020-7717CRITICAL9.8All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
CVE-2020-7716CRITICAL9.8All versions of package deeps are vulnerable to Prototype Pollution via the set function.
CVE-2020-7715CRITICAL9.8All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
CVE-2020-7714CRITICAL9.8All versions of package confucious are vulnerable to Prototype Pollution via the set function.
CVE-2020-7713CRITICAL9.8All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
CVE-2020-25062CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of i...
CVE-2020-25061CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows p...
CVE-2020-25058CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management servic...
CVE-2020-25057CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not properly restrict APK inst...
CVE-2020-25055CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows ...
CVE-2020-25054CRITICAL9.1An issue was discovered on Samsung mobile devices with software through 2020-04-02 (Exynos modem chipsets). There is a h...
CVE-2020-25053CRITICAL9.8An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code...
CVE-2020-25052CRITICAL9.8An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to...
CVE-2020-25049CRITICAL9.8An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DE...
CVE-2020-7522CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC E...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now