2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9769 | CRITICAL | 9.8 | 1.1% | Apr 1, 2020 | Multiple issues were addressed by updating to version 8.1.1850. This issue is fixed in macOS Catalina 10.15.4. Multiple ... |
| CVE-2020-3911 | CRITICAL | 9.8 | 1.6% | Apr 1, 2020 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Ca... |
| CVE-2020-3910 | CRITICAL | 9.8 | 1.6% | Apr 1, 2020 | A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Ca... |
| CVE-2020-3909 | CRITICAL | 9.8 | 3.0% | Apr 1, 2020 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Ca... |
| CVE-2020-10867 | CRITICAL | 9.8 | 2.2% | Apr 1, 2020 | An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi... |
| CVE-2020-11455 | CRITICAL | 9.8 | 97.0% | Apr 1, 2020 | LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM... |
| CVE-2020-7947 | CRITICAL | 9.8 | 2.8% | Apr 1, 2020 | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain... |
| CVE-2020-5344 | CRITICAL | 9.8 | 3.7% | Mar 31, 2020 | Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer ove... |
| CVE-2020-6008 | CRITICAL | 9.8 | 3.8% | Mar 31, 2020 | LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution |
| CVE-2020-4208 | CRITICAL | 9.8 | 1.8% | Mar 31, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key... |
| CVE-2020-10595 | CRITICAL | 9.8 | 4.8% | Mar 31, 2020 | pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental pr... |
| CVE-2020-7611 | CRITICAL | 9.8 | 1.8% | Mar 30, 2020 | All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable... |
| CVE-2020-11105 | CRITICAL | 9.8 | 2.0% | Mar 30, 2020 | An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw po... |
| CVE-2020-10374 | CRITICAL | 9.8 | 4.7% | Mar 30, 2020 | A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command exe... |
| CVE-2020-5723 | CRITICAL | 9.8 | 5.7% | Mar 30, 2020 | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta... |
| CVE-2020-7610 | CRITICAL | 9.8 | 2.2% | Mar 30, 2020 | All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknow... |
| CVE-2020-10956 | CRITICAL | 9.8 | 1.4% | Mar 27, 2020 | GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature. |
| CVE-2020-3936 | CRITICAL | 9.8 | 1.2% | Mar 27, 2020 | UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, ... |
| CVE-2020-10993 | CRITICAL | 9.1 | 1.3% | Mar 27, 2020 | Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java. |
| CVE-2020-10992 | CRITICAL | 9.8 | 1.3% | Mar 27, 2020 | Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. |
| CVE-2020-10991 | CRITICAL | 9.8 | 1.3% | Mar 27, 2020 | Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java |
| CVE-2020-10990 | CRITICAL | 9.8 | 1.2% | Mar 27, 2020 | An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.j... |
| CVE-2020-10828 | CRITICAL | 9.8 | 20.9% | Mar 26, 2020 | A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote ... |
| CVE-2020-10827 | CRITICAL | 9.8 | 20.9% | Mar 26, 2020 | A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote ... |
| CVE-2020-10826 | CRITICAL | 9.8 | 39.4% | Mar 26, 2020 | /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to ach... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now