2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1693 | CRITICAL | 9.8 | 4.2% | Feb 17, 2020 | A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api ... |
| CVE-2020-9006 | CRITICAL | 9.8 | 8.6% | Feb 17, 2020 | The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups funct... |
| CVE-2020-8518 | CRITICAL | 9.8 | 71.1% | Feb 17, 2020 | Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu... |
| CVE-2020-8427 | CRITICAL | 9.8 | 1.5% | Feb 17, 2020 | In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that... |
| CVE-2020-5531 | CRITICAL | 9.8 | 2.0% | Feb 17, 2020 | Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V,... |
| CVE-2020-9027 | CRITICAL | 9.8 | 3.0% | Feb 17, 2020 | ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The N... |
| CVE-2020-9026 | CRITICAL | 9.8 | 3.1% | Feb 17, 2020 | ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NT... |
| CVE-2020-9024 | CRITICAL | 9.8 | 1.8% | Feb 17, 2020 | Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (e... |
| CVE-2020-9023 | CRITICAL | 9.8 | 1.5% | Feb 17, 2020 | Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured wit... |
| CVE-2020-9021 | CRITICAL | 9.8 | 2.1% | Feb 17, 2020 | Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.... |
| CVE-2020-9020 | CRITICAL | 9.8 | 2.5% | Feb 17, 2020 | Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timecon... |
| CVE-2020-8129 | CRITICAL | 9.8 | 2.9% | Feb 14, 2020 | An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execu... |
| CVE-2020-8128 | CRITICAL | 9.8 | 2.6% | Feb 14, 2020 | An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attack... |
| CVE-2020-8612 | CRITICAL | 9 | 1.7% | Feb 14, 2020 | In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately ... |
| CVE-2020-8803 | CRITICAL | 9.8 | 3.3% | Feb 13, 2020 | SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospe... |
| CVE-2020-8802 | CRITICAL | 9.8 | 2.6% | Feb 13, 2020 | SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation. |
| CVE-2020-8614 | CRITICAL | 9.8 | 2.6% | Feb 13, 2020 | An issue was discovered on Askey AP4000W TDC_V1.01.003 devices. An attacker can perform Remote Code Execution (RCE) by s... |
| CVE-2020-3763 | CRITICAL | 9.8 | 3.6% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3762 | CRITICAL | 9.8 | 3.4% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3760 | CRITICAL | 9.8 | 7.1% | Feb 13, 2020 | Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could l... |
| CVE-2020-3754 | CRITICAL | 9.8 | 4.9% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3752 | CRITICAL | 9.8 | 5.1% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3751 | CRITICAL | 9.8 | 4.9% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3750 | CRITICAL | 9.8 | 4.9% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3749 | CRITICAL | 9.8 | 4.9% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now