2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7630CRITICAL9.8git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name ...
CVE-2020-7629CRITICAL9.8install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the opti...
CVE-2020-7628CRITICAL9.8umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sani...
CVE-2020-7627CRITICAL9.8node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'ar...
CVE-2020-7626CRITICAL9.8karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config ar...
CVE-2020-7625CRITICAL9.8op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url funct...
CVE-2020-7624CRITICAL9.8effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argume...
CVE-2020-10515CRITICAL9.8STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-...
CVE-2020-9067HIGH8There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to p...
CVE-2020-7623CRITICAL9.8jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argume...
CVE-2020-7621CRITICAL9.8strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as pa...
CVE-2020-7620CRITICAL9.8pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'po...
CVE-2020-7619CRITICAL9.8get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of th...
CVE-2020-11494MEDIUM4.4An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attacke...
CVE-2020-8835HIGH7.8In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bou...
CVE-2020-7617CRITICAL9.8ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying prop...
CVE-2020-11444HIGH8.8Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
CVE-2020-11107HIGH8.8An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged...
CVE-2020-8423HIGH7.2A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated...
CVE-2020-11453MEDIUM5.3Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed throug...
CVE-2020-11452MEDIUM4.3Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URL...
CVE-2020-9349HIGH7.5The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service wit...
CVE-2020-6852CRITICAL9.8CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access,...
CVE-2020-4325MEDIUM6.5The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not pr...
CVE-2020-4304MEDIUM6.1IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnera...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now