2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1938 | CRITICAL | 9.8 | 99.3% | Feb 24, 2020 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc... |
| CVE-2020-9374 | CRITICAL | 9.8 | 42.0% | Feb 24, 2020 | On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit... |
| CVE-2020-9366 | CRITICAL | 9.8 | 2.6% | Feb 24, 2020 | A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted outp... |
| CVE-2020-4222 | CRITICAL | 9.8 | 15.5% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-4213 | CRITICAL | 9.8 | 15.5% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-4212 | CRITICAL | 9.8 | 15.0% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-4211 | CRITICAL | 9.8 | 71.1% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-4210 | CRITICAL | 9.8 | 15.5% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-9355 | CRITICAL | 9.8 | 2.2% | Feb 23, 2020 | danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled. |
| CVE-2020-9352 | CRITICAL | 9.8 | 1.9% | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL fea... |
| CVE-2020-9039 | CRITICAL | 9.8 | 3.8% | Feb 22, 2020 | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Per... |
| CVE-2020-6841 | CRITICAL | 9.8 | 2.8% | Feb 21, 2020 | D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharac... |
| CVE-2020-9015 | CRITICAL | 9.8 | 16.1% | Feb 20, 2020 | Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly oth... |
| CVE-2020-8990 | CRITICAL | 9.1 | 1.0% | Feb 20, 2020 | Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation. |
| CVE-2020-3765 | CRITICAL | 9.8 | 5.8% | Feb 20, 2020 | Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could... |
| CVE-2020-6970 | CRITICAL | 9.8 | 2.5% | Feb 19, 2020 | A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have bee... |
| CVE-2020-3943 | CRITICAL | 9.8 | 2.3% | Feb 19, 2020 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is ... |
| CVE-2020-3158 | CRITICAL | 9.1 | 2.5% | Feb 19, 2020 | A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthentic... |
| CVE-2020-6061 | CRITICAL | 9.8 | 5.0% | Feb 19, 2020 | An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A... |
| CVE-2020-8441 | CRITICAL | 9.8 | 4.8% | Feb 19, 2020 | JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function... |
| CVE-2020-7796 | CRITICAL | 9.8 | 85.4% | Feb 18, 2020 | Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enab... |
| CVE-2020-7450 | CRITICAL | 9.8 | 2.4% | Feb 18, 2020 | In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-S... |
| CVE-2020-8012 | CRITICAL | 9.8 | 77.6% | Feb 18, 2020 | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi... |
| CVE-2020-8010 | CRITICAL | 9.8 | 48.7% | Feb 18, 2020 | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vu... |
| CVE-2020-8768 | CRITICAL | 9.4 | 1.8% | Feb 17, 2020 | An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now