2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3746 | CRITICAL | 9.8 | 4.9% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3745 | CRITICAL | 9.8 | 4.9% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3743 | CRITICAL | 9.8 | 4.9% | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an... |
| CVE-2020-3742 | CRITICAL | 9.8 | 5.7% | Feb 13, 2020 | Adobe Acrobat and Reader versions, 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, a... |
| CVE-2020-3740 | CRITICAL | 9.8 | 5.0% | Feb 13, 2020 | Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead ... |
| CVE-2020-8962 | CRITICAL | 9.8 | 1.8% | Feb 13, 2020 | A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcp... |
| CVE-2020-8953 | CRITICAL | 9.8 | 1.3% | Feb 13, 2020 | OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor... |
| CVE-2020-8964 | CRITICAL | 9.8 | 3.7% | Feb 13, 2020 | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007... |
| CVE-2020-8963 | CRITICAL | 9.8 | 2.7% | Feb 13, 2020 | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007... |
| CVE-2020-7209 | CRITICAL | 9.8 | 98.8% | Feb 13, 2020 | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. |
| CVE-2020-8955 | CRITICAL | 9.8 | 3.7% | Feb 12, 2020 | irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of se... |
| CVE-2020-3934 | CRITICAL | 9.8 | 1.4% | Feb 11, 2020 | TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pr... |
| CVE-2020-8840 | CRITICAL | 9.8 | 26.6% | Feb 10, 2020 | FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apac... |
| CVE-2020-7060 | CRITICAL | 9.1 | 8.9% | Feb 10, 2020 | When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.... |
| CVE-2020-7059 | CRITICAL | 9.1 | 7.4% | Feb 10, 2020 | When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 an... |
| CVE-2020-6770 | CRITICAL | 9.8 | 3.6% | Feb 7, 2020 | Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker ... |
| CVE-2020-8796 | CRITICAL | 9.8 | 2.9% | Feb 7, 2020 | Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the serve... |
| CVE-2020-6769 | CRITICAL | 9.1 | 2.2% | Feb 7, 2020 | Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote... |
| CVE-2020-8656 | CRITICAL | 9.8 | 84.6% | Feb 7, 2020 | An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe... |
| CVE-2020-8645 | CRITICAL | 9.8 | 1.8% | Feb 7, 2020 | An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job a... |
| CVE-2020-6760 | CRITICAL | 9.8 | 1.7% | Feb 6, 2020 | Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry... |
| CVE-2020-8657 | CRITICAL | 9.8 | 91.9% | Feb 6, 2020 | An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include... |
| CVE-2020-8772 | CRITICAL | 9.8 | 87.9% | Feb 6, 2020 | The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in in... |
| CVE-2020-8771 | CRITICAL | 9.8 | 46.5% | Feb 6, 2020 | The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFI... |
| CVE-2020-8636 | CRITICAL | 9.8 | 4.0% | Feb 6, 2020 | An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution . |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now