2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8644 | CRITICAL | 9.8 | 86.7% | Feb 5, 2020 | PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. |
| CVE-2020-6754 | CRITICAL | 9.8 | 94.8% | Feb 5, 2020 | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to ... |
| CVE-2020-6969 | CRITICAL | 9.8 | 2.2% | Feb 5, 2020 | It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an ... |
| CVE-2020-6174 | CRITICAL | 9.8 | 1.0% | Feb 5, 2020 | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. |
| CVE-2020-8114 | CRITICAL | 9.8 | 1.4% | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission |
| CVE-2020-8125 | CRITICAL | 9.8 | 4.1% | Feb 4, 2020 | Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may re... |
| CVE-2020-6058 | CRITICAL | 9.1 | 2.4% | Feb 4, 2020 | An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A ... |
| CVE-2020-5235 | CRITICAL | 9.8 | 1.7% | Feb 4, 2020 | There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is ... |
| CVE-2020-8597 | CRITICAL | 9.8 | 19.4% | Feb 3, 2020 | eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. |
| CVE-2020-8592 | CRITICAL | 9.8 | 1.4% | Feb 3, 2020 | eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password featu... |
| CVE-2020-8591 | CRITICAL | 9.8 | 1.4% | Feb 3, 2020 | eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r re... |
| CVE-2020-8547 | CRITICAL | 9.8 | 5.9% | Feb 3, 2020 | phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which m... |
| CVE-2020-8510 | CRITICAL | 9.8 | 1.2% | Feb 3, 2020 | An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of... |
| CVE-2020-7471 | CRITICAL | 9.8 | 65.3% | Feb 3, 2020 | Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a ... |
| CVE-2020-8508 | CRITICAL | 9.8 | 1.7% | Feb 3, 2020 | nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of func... |
| CVE-2020-8515 | CRITICAL | 9.8 | 100.0% | Feb 1, 2020 | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow... |
| CVE-2020-8440 | CRITICAL | 9.8 | 2.8% | Jan 31, 2020 | controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by ... |
| CVE-2020-7956 | CRITICAL | 9.8 | 1.0% | Jan 31, 2020 | HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates use... |
| CVE-2020-5206 | CRITICAL | 10 | 1.3% | Jan 30, 2020 | In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume prope... |
| CVE-2020-8447 | CRITICAL | 9.8 | 1.9% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ... |
| CVE-2020-8445 | CRITICAL | 9.8 | 2.3% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control c... |
| CVE-2020-8444 | CRITICAL | 9.8 | 2.5% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ... |
| CVE-2020-8443 | CRITICAL | 9.8 | 2.7% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an... |
| CVE-2020-8432 | CRITICAL | 9.8 | 3.7% | Jan 29, 2020 | In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double free... |
| CVE-2020-3718 | CRITICAL | 9.8 | 7.5% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security by... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now