2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7630 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name ... |
| CVE-2020-7629 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the opti... |
| CVE-2020-7628 | CRITICAL | 9.8 | 1.7% | Apr 2, 2020 | umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sani... |
| CVE-2020-7627 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'ar... |
| CVE-2020-7626 | CRITICAL | 9.8 | 4.2% | Apr 2, 2020 | karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config ar... |
| CVE-2020-7625 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url funct... |
| CVE-2020-7624 | CRITICAL | 9.8 | 4.1% | Apr 2, 2020 | effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argume... |
| CVE-2020-10515 | CRITICAL | 9.8 | 2.9% | Apr 2, 2020 | STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-... |
| CVE-2020-9067 | HIGH | 8 | 0.6% | Apr 2, 2020 | There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to p... |
| CVE-2020-7623 | CRITICAL | 9.8 | 3.5% | Apr 2, 2020 | jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argume... |
| CVE-2020-7621 | CRITICAL | 9.8 | 2.9% | Apr 2, 2020 | strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as pa... |
| CVE-2020-7620 | CRITICAL | 9.8 | 2.1% | Apr 2, 2020 | pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'po... |
| CVE-2020-7619 | CRITICAL | 9.8 | 2.1% | Apr 2, 2020 | get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of th... |
| CVE-2020-11494 | MEDIUM | 4.4 | 0.7% | Apr 2, 2020 | An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attacke... |
| CVE-2020-8835 | HIGH | 7.8 | 6.1% | Apr 2, 2020 | In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bou... |
| CVE-2020-7617 | CRITICAL | 9.8 | 0.9% | Apr 2, 2020 | ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying prop... |
| CVE-2020-11444 | HIGH | 8.8 | 8.5% | Apr 2, 2020 | Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control. |
| CVE-2020-11107 | HIGH | 8.8 | 22.5% | Apr 2, 2020 | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged... |
| CVE-2020-8423 | HIGH | 7.2 | 9.3% | Apr 2, 2020 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated... |
| CVE-2020-11453 | MEDIUM | 5.3 | 2.7% | Apr 2, 2020 | Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed throug... |
| CVE-2020-11452 | MEDIUM | 4.3 | 1.2% | Apr 2, 2020 | Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URL... |
| CVE-2020-9349 | HIGH | 7.5 | 1.5% | Apr 2, 2020 | The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service wit... |
| CVE-2020-6852 | CRITICAL | 9.8 | 2.4% | Apr 2, 2020 | CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access,... |
| CVE-2020-4325 | MEDIUM | 6.5 | 1.5% | Apr 2, 2020 | The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not pr... |
| CVE-2020-4304 | MEDIUM | 6.1 | 0.8% | Apr 2, 2020 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnera... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now