2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8599 | CRITICAL | 9.8 | 11.6% | Mar 18, 2020 | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to... |
| CVE-2020-8598 | CRITICAL | 9.8 | 13.2% | Mar 18, 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl... |
| CVE-2020-10121 | CRITICAL | 9.8 | 1.8% | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546). |
| CVE-2020-10119 | CRITICAL | 9.8 | 2.2% | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). |
| CVE-2020-10118 | CRITICAL | 9.1 | 1.0% | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543). |
| CVE-2020-10117 | CRITICAL | 9.1 | 1.0% | Mar 17, 2020 | cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542). |
| CVE-2020-10380 | CRITICAL | 9.8 | 1.1% | Mar 17, 2020 | RMySQL through 0.10.19 allows SQL Injection. |
| CVE-2020-9347 | CRITICAL | 9.8 | 7.8% | Mar 16, 2020 | Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name tha... |
| CVE-2020-8786 | CRITICAL | 9.8 | 1.1% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4). |
| CVE-2020-8785 | CRITICAL | 9.8 | 1.1% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4). |
| CVE-2020-8784 | CRITICAL | 9.8 | 1.1% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4). |
| CVE-2020-8783 | CRITICAL | 9.8 | 1.1% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4). |
| CVE-2020-5847 | CRITICAL | 9.8 | 95.8% | Mar 16, 2020 | Unraid through 6.8.0 allows Remote Code Execution. |
| CVE-2020-6990 | CRITICAL | 9.8 | 4.2% | Mar 16, 2020 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont... |
| CVE-2020-10243 | CRITICAL | 9.8 | 2.0% | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a S... |
| CVE-2020-10230 | CRITICAL | 9.8 | 14.7% | Mar 16, 2020 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/adm... |
| CVE-2020-5547 | CRITICAL | 9.8 | 2.3% | Mar 16, 2020 | Resource Management Errors vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 seri... |
| CVE-2020-5545 | CRITICAL | 9.8 | 2.3% | Mar 16, 2020 | TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and ear... |
| CVE-2020-5544 | CRITICAL | 9.8 | 2.4% | Mar 16, 2020 | Null Pointer Dereference vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series... |
| CVE-2020-5543 | CRITICAL | 9.8 | 2.1% | Mar 16, 2020 | TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and ear... |
| CVE-2020-5542 | CRITICAL | 9.8 | 2.3% | Mar 16, 2020 | Buffer error vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D ... |
| CVE-2020-7607 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in ... |
| CVE-2020-7606 | CRITICAL | 9.8 | 2.6% | Mar 15, 2020 | docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the fu... |
| CVE-2020-7605 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of '... |
| CVE-2020-7604 | CRITICAL | 9.8 | 2.5% | Mar 15, 2020 | pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be cont... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now