2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10837 | CRITICAL | 9.8 | 0.9% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet ... |
| CVE-2020-10836 | CRITICAL | 9.8 | 0.4% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The Widev... |
| CVE-2020-10835 | CRITICAL | 9.8 | 1.5% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with any (before February 2020 for Exynos modem chipsets) software. Th... |
| CVE-2020-6972 | CRITICAL | 9.1 | 1.3% | Mar 24, 2020 | In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by... |
| CVE-2020-10938 | CRITICAL | 9.8 | 5.2% | Mar 24, 2020 | GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in m... |
| CVE-2020-1747 | CRITICAL | 9.8 | 5.3% | Mar 24, 2020 | A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code... |
| CVE-2020-1944 | CRITICAL | 9.8 | 2.7% | Mar 23, 2020 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling at... |
| CVE-2020-10879 | CRITICAL | 9.8 | 83.9% | Mar 23, 2020 | rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nod... |
| CVE-2020-8868 | CRITICAL | 9.8 | 9.5% | Mar 23, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve ... |
| CVE-2020-6967 | CRITICAL | 9.8 | 5.4% | Mar 23, 2020 | In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platfor... |
| CVE-2020-7480 | CRITICAL | 9.8 | 1.5% | Mar 23, 2020 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versi... |
| CVE-2020-5722 | CRITICAL | 9.8 | 83.9% | Mar 23, 2020 | The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte... |
| CVE-2020-7475 | CRITICAL | 9.8 | 1.5% | Mar 23, 2020 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective... |
| CVE-2020-9760 | CRITICAL | 9.8 | 2.2% | Mar 23, 2020 | An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with... |
| CVE-2020-10661 | CRITICAL | 9.1 | 1.1% | Mar 23, 2020 | HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing neste... |
| CVE-2020-9752 | CRITICAL | 9.8 | 1.1% | Mar 23, 2020 | Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system... |
| CVE-2020-10806 | CRITICAL | 9.8 | 2.3% | Mar 22, 2020 | eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 20... |
| CVE-2020-10799 | CRITICAL | 9.8 | 1.4% | Mar 20, 2020 | The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call. |
| CVE-2020-8137 | CRITICAL | 9.8 | 4.2% | Mar 20, 2020 | Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be contr... |
| CVE-2020-8135 | CRITICAL | 9.8 | 1.3% | Mar 20, 2020 | The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attack... |
| CVE-2020-7961 | CRITICAL | 9.8 | 99.8% | Mar 20, 2020 | Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c... |
| CVE-2020-9423 | CRITICAL | 9.8 | 4.9% | Mar 18, 2020 | LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of ... |
| CVE-2020-10674 | CRITICAL | 9.8 | 1.3% | Mar 18, 2020 | PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argumen... |
| CVE-2020-3922 | CRITICAL | 9.8 | 1.5% | Mar 18, 2020 | LisoMail, by ArmorX, allows SQL Injections, attackers can access the database without authentication via a URL parameter... |
| CVE-2020-8600 | CRITICAL | 9.8 | 4.2% | Mar 18, 2020 | Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now