2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10181 | CRITICAL | 9.8 | 14.2% | Mar 11, 2020 | goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevate... |
| CVE-2020-5203 | CRITICAL | 9.8 | 2.1% | Mar 11, 2020 | In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled... |
| CVE-2020-10376 | CRITICAL | 9.8 | 1.1% | Mar 11, 2020 | Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an... |
| CVE-2020-6207 | CRITICAL | 9.8 | 98.4% | Mar 10, 2020 | SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an... |
| CVE-2020-6203 | CRITICAL | 9.1 | 1.9% | Mar 10, 2020 | SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to... |
| CVE-2020-6198 | CRITICAL | 9.8 | 1.4% | Mar 10, 2020 | SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This... |
| CVE-2020-9044 | CRITICAL | 9.1 | 1.3% | Mar 10, 2020 | XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks... |
| CVE-2020-5253 | CRITICAL | 9.8 | 0.5% | Mar 10, 2020 | NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethack... |
| CVE-2020-10255 | CRITICAL | 9 | 2.5% | Mar 10, 2020 | Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations aga... |
| CVE-2020-10257 | CRITICAL | 9.8 | 8.9% | Mar 10, 2020 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST... |
| CVE-2020-9758 | CRITICAL | 9.6 | 2.5% | Mar 9, 2020 | An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the ... |
| CVE-2020-10250 | CRITICAL | 9.8 | 2.6% | Mar 9, 2020 | BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG... |
| CVE-2020-10233 | CRITICAL | 9.1 | 2.4% | Mar 9, 2020 | In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs... |
| CVE-2020-10232 | CRITICAL | 9.8 | 2.4% | Mar 9, 2020 | In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file t... |
| CVE-2020-10225 | CRITICAL | 9.8 | 4.3% | Mar 8, 2020 | An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The ... |
| CVE-2020-10224 | CRITICAL | 9.8 | 5.5% | Mar 8, 2020 | An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. T... |
| CVE-2020-10220 | CRITICAL | 9.8 | 99.7% | Mar 7, 2020 | An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php... |
| CVE-2020-10212 | CRITICAL | 9.8 | 1.5% | Mar 7, 2020 | upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking... |
| CVE-2020-5328 | CRITICAL | 9.8 | 1.4% | Mar 6, 2020 | Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough aut... |
| CVE-2020-5327 | CRITICAL | 9.8 | 3.6% | Mar 6, 2020 | Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerabi... |
| CVE-2020-8113 | CRITICAL | 9.8 | 1.4% | Mar 6, 2020 | GitLab 10.7 and later through 12.7.2 has Incorrect Access Control. |
| CVE-2020-10189 | CRITICAL | 9.8 | 99.9% | Mar 6, 2020 | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d... |
| CVE-2020-10188 | CRITICAL | 9.8 | 74.5% | Mar 6, 2020 | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or... |
| CVE-2020-10180 | CRITICAL | 9.8 | 1.6% | Mar 5, 2020 | The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects ve... |
| CVE-2020-9380 | CRITICAL | 9.8 | 4.0% | Mar 5, 2020 | IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now