2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9290 | HIGH | 7.8 | 0.6% | Mar 15, 2020 | An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attack... |
| CVE-2020-9287 | HIGH | 7.8 | 0.6% | Mar 15, 2020 | An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with ... |
| CVE-2020-7607 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in ... |
| CVE-2020-7606 | CRITICAL | 9.8 | 2.6% | Mar 15, 2020 | docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the fu... |
| CVE-2020-7605 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of '... |
| CVE-2020-7604 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be cont... |
| CVE-2020-7603 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports fun... |
| CVE-2020-7602 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" fu... |
| CVE-2020-7601 | CRITICAL | 9.8 | 2.6% | Mar 15, 2020 | gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the ... |
| CVE-2020-10594 | CRITICAL | 9.1 | 1.3% | Mar 15, 2020 | An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated tok... |
| CVE-2020-0088 | MEDIUM | 6.5 | 0.7% | Mar 15, 2020 | In parseTrackFragmentRun of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. ... |
| CVE-2020-0086 | CRITICAL | 9.8 | 0.6% | Mar 15, 2020 | In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to arb... |
| CVE-2020-10591 | HIGH | 7.5 | 2.0% | Mar 15, 2020 | An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potential... |
| CVE-2020-10589 | HIGH | 7.8 | 0.4% | Mar 15, 2020 | v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user... |
| CVE-2020-10588 | HIGH | 7.8 | 0.4% | Mar 15, 2020 | v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by... |
| CVE-2020-8141 | HIGH | 8.8 | 2.1% | Mar 15, 2020 | The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control t... |
| CVE-2020-10587 | HIGH | 7.8 | 0.5% | Mar 14, 2020 | antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo c... |
| CVE-2020-10578 | HIGH | 7.5 | 1.2% | Mar 14, 2020 | An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1. |
| CVE-2020-10577 | MEDIUM | 4.8 | 0.5% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property ... |
| CVE-2020-10576 | MEDIUM | 5.9 | 0.6% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition t... |
| CVE-2020-10575 | MEDIUM | 4.2 | 0.5% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session man... |
| CVE-2020-10574 | CRITICAL | 9.8 | 1.2% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "quer... |
| CVE-2020-10573 | HIGH | 7.5 | 0.8% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms... |
| CVE-2020-10571 | CRITICAL | 9.8 | 1.7% | Mar 14, 2020 | An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious... |
| CVE-2020-10568 | HIGH | 8.8 | 1.7% | Mar 14, 2020 | The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This lea... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now