2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25705 | HIGH | 7.4 | 6.7% | Nov 17, 2020 | A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off... |
| CVE-2020-15349 | HIGH | 7.8 | 0.7% | Nov 17, 2020 | BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool i... |
| CVE-2020-14389 | HIGH | 8.1 | 0.8% | Nov 17, 2020 | It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources... |
| CVE-2020-26224 | HIGH | 7.5 | 1.7% | Nov 16, 2020 | In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logg... |
| CVE-2020-28693 | HIGH | 8.8 | 2.5% | Nov 16, 2020 | An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code t... |
| CVE-2020-26217 | HIGH | 8.8 | 85.0% | Nov 16, 2020 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to ru... |
| CVE-2020-26509 | HIGH | 7.5 | 1.1% | Nov 16, 2020 | Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service. |
| CVE-2020-28692 | HIGH | 7.2 | 1.6% | Nov 16, 2020 | In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for exec... |
| CVE-2020-23490 | HIGH | 7.5 | 2.6% | Nov 16, 2020 | There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can... |
| CVE-2020-23489 | HIGH | 8.8 | 2.3% | Nov 16, 2020 | The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion ... |
| CVE-2020-4700 | HIGH | 8.8 | 1.2% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenti... |
| CVE-2020-4655 | HIGH | 8.8 | 1.3% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL in... |
| CVE-2020-4647 | HIGH | 8.8 | 1.0% | Nov 16, 2020 | IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote a... |
| CVE-2020-4476 | HIGH | 7.5 | 1.5% | Nov 16, 2020 | IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain se... |
| CVE-2020-28723 | HIGH | 7.5 | 1.6% | Nov 16, 2020 | Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1. |
| CVE-2020-27623 | HIGH | 7.5 | 1.1% | Nov 16, 2020 | JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances. |
| CVE-2020-27423 | HIGH | 7.5 | 6.4% | Nov 16, 2020 | Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial o... |
| CVE-2020-27191 | HIGH | 7.5 | 8.4% | Nov 16, 2020 | LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the ind... |
| CVE-2020-13769 | HIGH | 8.8 | 2.6% | Nov 16, 2020 | LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device r... |
| CVE-2020-25209 | HIGH | 7.5 | 2.4% | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure ... |
| CVE-2020-25013 | HIGH | 7.5 | 1.4% | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler. |
| CVE-2020-8897 | HIGH | 8.1 | 0.4% | Nov 16, 2020 | A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2... |
| CVE-2020-5659 | HIGH | 8.8 | 1.1% | Nov 16, 2020 | SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary S... |
| CVE-2020-28649 | HIGH | 8.8 | 0.8% | Nov 16, 2020 | The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file... |
| CVE-2020-28648 | HIGH | 8.8 | 6.1% | Nov 16, 2020 | Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now