2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8273 | HIGH | 8.8 | 2.4% | Nov 16, 2020 | Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8... |
| CVE-2020-8272 | HIGH | 7.5 | 1.5% | Nov 16, 2020 | Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1... |
| CVE-2020-8270 | HIGH | 8.8 | 3.3% | Nov 16, 2020 | An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD version... |
| CVE-2020-8269 | HIGH | 8.8 | 2.6% | Nov 16, 2020 | An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, ... |
| CVE-2020-8259 | HIGH | 8.1 | 0.7% | Nov 16, 2020 | Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the... |
| CVE-2020-5666 | HIGH | 7.5 | 8.4% | Nov 16, 2020 | Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '... |
| CVE-2020-2492 | HIGH | 7.2 | 1.7% | Nov 16, 2020 | If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue... |
| CVE-2020-2490 | HIGH | 7.2 | 2.2% | Nov 16, 2020 | If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue... |
| CVE-2020-25695 | HIGH | 8.8 | 46.4% | Nov 16, 2020 | A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9... |
| CVE-2020-25694 | HIGH | 8.1 | 1.6% | Nov 16, 2020 | A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9... |
| CVE-2020-28268 | HIGH | 7.5 | 3.4% | Nov 15, 2020 | Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial o... |
| CVE-2020-15481 | HIGH | 7.8 | 0.6% | Nov 13, 2020 | An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 B... |
| CVE-2020-5796 | HIGH | 7.8 | 1.9% | Nov 13, 2020 | Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the... |
| CVE-2020-27217 | HIGH | 7.5 | 1.3% | Nov 13, 2020 | In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received fro... |
| CVE-2020-12313 | HIGH | 8.8 | 0.9% | Nov 13, 2020 | Insufficient control flow management in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an u... |
| CVE-2020-8583 | HIGH | 7.5 | 1.1% | Nov 13, 2020 | Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could a... |
| CVE-2020-6019 | HIGH | 7.5 | 2.8% | Nov 13, 2020 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConn... |
| CVE-2020-26222 | HIGH | 8.8 | 2.9% | Nov 13, 2020 | Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Jav... |
| CVE-2020-25557 | HIGH | 8.8 | 9.9% | Nov 13, 2020 | In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. A... |
| CVE-2020-25538 | HIGH | 8.8 | 9.9% | Nov 13, 2020 | An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and r... |
| CVE-2020-25165 | HIGH | 7.5 | 1.7% | Nov 13, 2020 | BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The ... |
| CVE-2020-25155 | HIGH | 7.5 | 0.7% | Nov 13, 2020 | The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information... |
| CVE-2020-25151 | HIGH | 7.5 | 1.1% | Nov 13, 2020 | The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack... |
| CVE-2020-21667 | HIGH | 7.2 | 1.0% | Nov 13, 2020 | In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malic... |
| CVE-2020-6156 | HIGH | 7.8 | 1.3% | Nov 13, 2020 | A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now