2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9290HIGH7.8An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attack...
CVE-2020-9287HIGH7.8An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with ...
CVE-2020-7607CRITICAL9.8gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in ...
CVE-2020-7606CRITICAL9.8docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the fu...
CVE-2020-7605CRITICAL9.8gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of '...
CVE-2020-7604CRITICAL9.8pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be cont...
CVE-2020-7603CRITICAL9.8closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports fun...
CVE-2020-7602CRITICAL9.8node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" fu...
CVE-2020-7601CRITICAL9.8gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the ...
CVE-2020-10594CRITICAL9.1An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated tok...
CVE-2020-0088MEDIUM6.5In parseTrackFragmentRun of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. ...
CVE-2020-0086CRITICAL9.8In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to arb...
CVE-2020-10591HIGH7.5An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potential...
CVE-2020-10589HIGH7.8v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user...
CVE-2020-10588HIGH7.8v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by...
CVE-2020-8141HIGH8.8The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control t...
CVE-2020-10587HIGH7.8antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo c...
CVE-2020-10578HIGH7.5An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.
CVE-2020-10577MEDIUM4.8An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property ...
CVE-2020-10576MEDIUM5.9An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition t...
CVE-2020-10575MEDIUM4.2An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session man...
CVE-2020-10574CRITICAL9.8An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "quer...
CVE-2020-10573HIGH7.5An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms...
CVE-2020-10571CRITICAL9.8An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious...
CVE-2020-10568HIGH8.8The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This lea...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now