2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27602 | CRITICAL | 9.8 | 1.4% | Sep 29, 2022 | BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authTo... |
| CVE-2020-15347 | CRITICAL | 9.8 | 1.3% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account. |
| CVE-2020-15332 | CRITICAL | 9.8 | 0.9% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions. |
| CVE-2020-15331 | CRITICAL | 9.8 | 0.9% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess. |
| CVE-2020-19586 | CRITICAL | 9 | 1.2% | Sep 14, 2022 | Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via ... |
| CVE-2020-21516 | CRITICAL | 9.8 | 1.0% | Sep 6, 2022 | There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to exe... |
| CVE-2020-22669 | CRITICAL | 9.8 | 1.0% | Sep 2, 2022 | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can ... |
| CVE-2020-35527 | CRITICAL | 9.8 | 1.0% | Sep 1, 2022 | In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause. |
| CVE-2020-27836 | CRITICAL | 9.8 | 1.0% | Aug 22, 2022 | A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source r... |
| CVE-2020-27794 | CRITICAL | 9.1 | 0.9% | Aug 19, 2022 | A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modificati... |
| CVE-2020-36599 | CRITICAL | 9.8 | 1.0% | Aug 18, 2022 | lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. |
| CVE-2020-21642 | CRITICAL | 9.8 | 7.7% | Aug 15, 2022 | Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus befo... |
| CVE-2020-7795 | CRITICAL | 9.8 | 3.7% | Aug 2, 2022 | The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js. |
| CVE-2020-28453 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js. |
| CVE-2020-28451 | CRITICAL | 9.8 | 1.2% | Aug 2, 2022 | This affects the package image-tiler before 2.0.2. |
| CVE-2020-28437 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index... |
| CVE-2020-28434 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js. |
| CVE-2020-28433 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | This affects all versions of package node-latex-pdf. |
| CVE-2020-28425 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | This affects all versions of package curljs. |
| CVE-2020-28424 | CRITICAL | 9.8 | 0.7% | Aug 2, 2022 | This affects all versions of package s3-kilatstorage. |
| CVE-2020-28423 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | This affects all versions of package monorepo-build. |
| CVE-2020-7678 | CRITICAL | 9.8 | 0.9% | Jul 25, 2022 | This affects all versions of package node-import. The "params" argument of module function can be controlled by users wi... |
| CVE-2020-7677 | CRITICAL | 9.8 | 1.6% | Jul 25, 2022 | This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users with... |
| CVE-2020-28471 | CRITICAL | 9.8 | 1.1% | Jul 25, 2022 | This affects the package properties-reader before 2.2.0. |
| CVE-2020-28462 | CRITICAL | 9.8 | 0.8% | Jul 25, 2022 | This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that pars... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now