2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28366 | HIGH | 7.5 | 2.2% | Nov 18, 2020 | Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time ... |
| CVE-2020-28362 | HIGH | 7.5 | 3.8% | Nov 18, 2020 | Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. |
| CVE-2020-28091 | HIGH | 7.5 | 3.8% | Nov 18, 2020 | cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame... |
| CVE-2020-25406 | HIGH | 7.3 | 0.9% | Nov 18, 2020 | app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files. |
| CVE-2020-24297 | HIGH | 8.8 | 3.6% | Nov 18, 2020 | httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS com... |
| CVE-2020-7564 | HIGH | 8.8 | 1.1% | Nov 18, 2020 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server... |
| CVE-2020-7563 | HIGH | 8.8 | 1.1% | Nov 18, 2020 | A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premi... |
| CVE-2020-7562 | HIGH | 8.1 | 0.9% | Nov 18, 2020 | A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premiu... |
| CVE-2020-28914 | HIGH | 7.1 | 0.4% | Nov 17, 2020 | An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath vol... |
| CVE-2020-26552 | HIGH | 7.5 | 1.2% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints... |
| CVE-2020-26551 | HIGH | 7.5 | 0.9% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file. |
| CVE-2020-26550 | HIGH | 7.5 | 1.5% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated s... |
| CVE-2020-26549 | HIGH | 7.5 | 1.5% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests t... |
| CVE-2020-26548 | HIGH | 8.8 | 1.4% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can ... |
| CVE-2020-28136 | HIGH | 8.8 | 2.9% | Nov 17, 2020 | An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote... |
| CVE-2020-26405 | HIGH | 7.1 | 1.4% | Nov 17, 2020 | Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to sa... |
| CVE-2020-25400 | HIGH | 7.5 | 1.9% | Nov 17, 2020 | Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to acce... |
| CVE-2020-13958 | HIGH | 7.8 | 2.7% | Nov 17, 2020 | A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks po... |
| CVE-2020-27554 | HIGH | 7.5 | 0.7% | Nov 17, 2020 | Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists whi... |
| CVE-2020-27553 | HIGH | 7.5 | 1.5% | Nov 17, 2020 | In BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoo... |
| CVE-2020-21665 | HIGH | 7.2 | 0.9% | Nov 17, 2020 | In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be pas... |
| CVE-2020-7841 | HIGH | 8.8 | 1.5% | Nov 17, 2020 | Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution whe... |
| CVE-2020-28688 | HIGH | 8.8 | 11.9% | Nov 17, 2020 | The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo... |
| CVE-2020-28687 | HIGH | 8.8 | 11.9% | Nov 17, 2020 | The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upl... |
| CVE-2020-27192 | HIGH | 7.8 | 0.4% | Nov 17, 2020 | BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now