2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3716 | CRITICAL | 9.8 | 14.0% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserializa... |
| CVE-2020-7247 | CRITICAL | 9.8 | 99.0% | Jan 29, 2020 | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to ... |
| CVE-2020-5211 | CRITICAL | 9.8 | 1.1% | Jan 28, 2020 | In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a... |
| CVE-2020-4207 | CRITICAL | 9.8 | 4.5% | Jan 28, 2020 | IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by impr... |
| CVE-2020-5214 | CRITICAL | 9.8 | 1.1% | Jan 28, 2020 | In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash... |
| CVE-2020-5213 | CRITICAL | 9.8 | 1.1% | Jan 28, 2020 | In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow result... |
| CVE-2020-5212 | CRITICAL | 9.8 | 1.1% | Jan 28, 2020 | In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow... |
| CVE-2020-8086 | CRITICAL | 9.8 | 1.6% | Jan 28, 2020 | The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP addre... |
| CVE-2020-8088 | CRITICAL | 9.8 | 1.4% | Jan 27, 2020 | panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password has... |
| CVE-2020-8087 | CRITICAL | 9.8 | 6.3% | Jan 27, 2020 | SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network D... |
| CVE-2020-8001 | CRITICAL | 9.8 | 1.6% | Jan 27, 2020 | The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account. |
| CVE-2020-8000 | CRITICAL | 9.8 | 2.4% | Jan 27, 2020 | Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account. |
| CVE-2020-7999 | CRITICAL | 9.8 | 1.3% | Jan 27, 2020 | The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY. |
| CVE-2020-7995 | CRITICAL | 9.8 | 4.5% | Jan 26, 2020 | The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attem... |
| CVE-2020-7981 | CRITICAL | 9.8 | 1.5% | Jan 25, 2020 | sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with ... |
| CVE-2020-7980 | CRITICAL | 9.8 | 83.0% | Jan 25, 2020 | Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th... |
| CVE-2020-6966 | CRITICAL | 10 | 2.2% | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center... |
| CVE-2020-6965 | CRITICAL | 9.9 | 1.1% | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center... |
| CVE-2020-6963 | CRITICAL | 10 | 2.7% | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center... |
| CVE-2020-6962 | CRITICAL | 10 | 4.9% | Jan 24, 2020 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente... |
| CVE-2020-6961 | CRITICAL | 10 | 1.6% | Jan 24, 2020 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente... |
| CVE-2020-7245 | CRITICAL | 9.8 | 1.2% | Jan 23, 2020 | Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arb... |
| CVE-2020-7941 | CRITICAL | 9.8 | 2.3% | Jan 23, 2020 | A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some c... |
| CVE-2020-7109 | CRITICAL | 9.8 | 1.7% | Jan 22, 2020 | The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. |
| CVE-2020-6960 | CRITICAL | 9.8 | 1.1% | Jan 22, 2020 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now