2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15150 | CRITICAL | 9.8 | 3.3% | Sep 1, 2020 | There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) att... |
| CVE-2020-7727 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package gedi are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7726 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function. |
| CVE-2020-7725 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function. |
| CVE-2020-7724 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7723 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function. |
| CVE-2020-7722 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function. |
| CVE-2020-7721 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function. |
| CVE-2020-7719 | CRITICAL | 9.8 | 2.8% | Sep 1, 2020 | Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function. |
| CVE-2020-7718 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions. |
| CVE-2020-7717 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package dot-notes are vulnerable to Prototype Pollution via the create function. |
| CVE-2020-7716 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package deeps are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7715 | CRITICAL | 9.8 | 2.0% | Sep 1, 2020 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function. |
| CVE-2020-7714 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package confucious are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7713 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor. |
| CVE-2020-25062 | CRITICAL | 9.8 | 0.5% | Aug 31, 2020 | An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of i... |
| CVE-2020-25061 | CRITICAL | 9.8 | 0.4% | Aug 31, 2020 | An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows p... |
| CVE-2020-25058 | CRITICAL | 9.8 | 0.4% | Aug 31, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management servic... |
| CVE-2020-25057 | CRITICAL | 9.8 | 0.4% | Aug 31, 2020 | An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not properly restrict APK inst... |
| CVE-2020-25055 | CRITICAL | 9.8 | 0.4% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows ... |
| CVE-2020-25054 | CRITICAL | 9.1 | 1.2% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with software through 2020-04-02 (Exynos modem chipsets). There is a h... |
| CVE-2020-25053 | CRITICAL | 9.8 | 0.7% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code... |
| CVE-2020-25052 | CRITICAL | 9.8 | 0.6% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to... |
| CVE-2020-25049 | CRITICAL | 9.8 | 0.4% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DE... |
| CVE-2020-7522 | CRITICAL | 9.8 | 1.7% | Aug 31, 2020 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC E... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now