2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9370 | CRITICAL | 9.1 | 1.2% | Mar 5, 2020 | HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking. |
| CVE-2020-10106 | CRITICAL | 9.8 | 1.2% | Mar 5, 2020 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in in... |
| CVE-2020-9054 | CRITICAL | 9.8 | 100.0% | Mar 4, 2020 | Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command... |
| CVE-2020-9550 | CRITICAL | 9.8 | 0.7% | Mar 4, 2020 | Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attack... |
| CVE-2020-9477 | CRITICAL | 9.8 | 1.3% | Mar 4, 2020 | An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in... |
| CVE-2020-9761 | CRITICAL | 9.8 | 2.1% | Mar 4, 2020 | An issue was discovered in UNCTAD ASYCUDA World 2001 through 2020. The Java RMI Server has an Insecure Default Configura... |
| CVE-2020-9757 | CRITICAL | 9.8 | 73.4% | Mar 4, 2020 | The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed ... |
| CVE-2020-9751 | CRITICAL | 9.1 | 0.5% | Mar 3, 2020 | Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and exec... |
| CVE-2020-10018 | CRITICAL | 9.8 | 5.0% | Mar 2, 2020 | WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory co... |
| CVE-2020-1731 | CRITICAL | 9.8 | 1.3% | Mar 2, 2020 | A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator gene... |
| CVE-2020-9548 | CRITICAL | 9.8 | 18.3% | Mar 2, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-9547 | CRITICAL | 9.8 | 18.7% | Mar 2, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-9546 | CRITICAL | 9.8 | 4.6% | Mar 2, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-9465 | CRITICAL | 9.8 | 82.2% | Feb 28, 2020 | An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL... |
| CVE-2020-8132 | CRITICAL | 9.8 | 2.0% | Feb 28, 2020 | Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF fi... |
| CVE-2020-9434 | CRITICAL | 9.1 | 0.8% | Feb 27, 2020 | openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean... |
| CVE-2020-9433 | CRITICAL | 9.1 | 0.8% | Feb 27, 2020 | openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean ... |
| CVE-2020-9432 | CRITICAL | 9.1 | 0.8% | Feb 27, 2020 | openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean f... |
| CVE-2020-7061 | CRITICAL | 9.1 | 3.9% | Feb 27, 2020 | In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, c... |
| CVE-2020-7043 | CRITICAL | 9.1 | 2.4% | Feb 27, 2020 | An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate vali... |
| CVE-2020-3924 | CRITICAL | 9.8 | 1.3% | Feb 27, 2020 | DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers c... |
| CVE-2020-3923 | CRITICAL | 9.8 | 1.7% | Feb 27, 2020 | DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism... |
| CVE-2020-9406 | CRITICAL | 9.8 | 1.2% | Feb 26, 2020 | IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service. |
| CVE-2020-9398 | CRITICAL | 9.8 | 1.3% | Feb 25, 2020 | ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQ... |
| CVE-2020-8794 | CRITICAL | 9.8 | 88.5% | Feb 25, 2020 | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now