2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13543 | HIGH | 8.8 | 3.3% | Dec 3, 2020 | A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web... |
| CVE-2020-13542 | HIGH | 7.8 | 0.6% | Dec 3, 2020 | A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depend... |
| CVE-2020-13531 | HIGH | 8.8 | 2.7% | Dec 3, 2020 | A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specia... |
| CVE-2020-2324 | HIGH | 7.5 | 1.3% | Dec 3, 2020 | Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2020-2322 | HIGH | 7.5 | 1.3% | Dec 3, 2020 | Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attac... |
| CVE-2020-2321 | HIGH | 8.1 | 0.7% | Dec 3, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to s... |
| CVE-2020-28939 | HIGH | 7.2 | 1.7% | Dec 3, 2020 | OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability al... |
| CVE-2020-28937 | HIGH | 7.5 | 1.3% | Dec 3, 2020 | OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to acce... |
| CVE-2020-6021 | HIGH | 7.8 | 0.3% | Dec 3, 2020 | Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which t... |
| CVE-2020-6111 | HIGH | 7.5 | 4.6% | Dec 3, 2020 | An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Program... |
| CVE-2020-5680 | HIGH | 7.5 | 1.4% | Dec 3, 2020 | Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a den... |
| CVE-2020-5676 | HIGH | 7.5 | 1.8% | Dec 3, 2020 | GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vec... |
| CVE-2020-13493 | HIGH | 7.8 | 1.3% | Dec 2, 2020 | A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f... |
| CVE-2020-25638 | HIGH | 7.4 | 2.9% | Dec 2, 2020 | A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementatio... |
| CVE-2020-12524 | HIGH | 7.5 | 1.1% | Dec 2, 2020 | Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W ... |
| CVE-2020-29458 | HIGH | 8.8 | 0.7% | Dec 2, 2020 | Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem. |
| CVE-2020-5423 | HIGH | 7.5 | 1.1% | Dec 2, 2020 | CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticat... |
| CVE-2020-27813 | HIGH | 7.5 | 2.3% | Dec 2, 2020 | An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An att... |
| CVE-2020-14305 | HIGH | 8.1 | 5.1% | Dec 2, 2020 | An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functiona... |
| CVE-2020-8539 | HIGH | 7.8 | 2.3% | Dec 1, 2020 | Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an atta... |
| CVE-2020-28993 | HIGH | 7.5 | 2.8% | Dec 1, 2020 | A Directory Traversal vulnerability exists in ATX miniCMTS200a Broadband Gateway through 2.0 and Pico CMTS through 2.0. ... |
| CVE-2020-7547 | HIGH | 8.8 | 1.3% | Dec 1, 2020 | A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA So... |
| CVE-2020-7545 | HIGH | 7.2 | 2.0% | Dec 1, 2020 | A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Sof... |
| CVE-2020-25181 | HIGH | 8.8 | 2.0% | Dec 1, 2020 | WECON PLC Editor Versions 1.3.8 and prior has a heap-based buffer overflow vulnerabilities have been identified that may... |
| CVE-2020-25177 | HIGH | 8.8 | 1.7% | Dec 1, 2020 | WECON PLC Editor Versions 1.3.8 and prior has a stack-based buffer overflow vulnerability has been identified that may a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now