2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6959 | CRITICAL | 9.8 | 2.2% | Jan 22, 2020 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT... |
| CVE-2020-7229 | CRITICAL | 9.8 | 1.5% | Jan 21, 2020 | An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search en... |
| CVE-2020-7233 | CRITICAL | 9.8 | 1.7% | Jan 19, 2020 | KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Log... |
| CVE-2020-7048 | CRITICAL | 9.1 | 22.9% | Jan 16, 2020 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any ... |
| CVE-2020-2587 | CRITICAL | 9.9 | 1.5% | Jan 15, 2020 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Suppo... |
| CVE-2020-2586 | CRITICAL | 9.9 | 1.5% | Jan 15, 2020 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Suppo... |
| CVE-2020-2555 | CRITICAL | 9.8 | 97.1% | Jan 15, 2020 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su... |
| CVE-2020-2551 | CRITICAL | 9.8 | 93.2% | Jan 15, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor... |
| CVE-2020-2546 | CRITICAL | 9.8 | 5.1% | Jan 15, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - Java... |
| CVE-2020-0654 | CRITICAL | 9.1 | 3.5% | Jan 14, 2020 | A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to byp... |
| CVE-2020-0646 | CRITICAL | 9.8 | 99.2% | Jan 14, 2020 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N... |
| CVE-2020-0610 | CRITICAL | 9.8 | 65.3% | Jan 14, 2020 | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta... |
| CVE-2020-0609 | CRITICAL | 9.8 | 74.9% | Jan 14, 2020 | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta... |
| CVE-2020-5505 | CRITICAL | 9.8 | 44.3% | Jan 14, 2020 | Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction... |
| CVE-2020-6958 | CRITICAL | 9.1 | 2.4% | Jan 14, 2020 | An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other p... |
| CVE-2020-6948 | CRITICAL | 9.8 | 3.6% | Jan 13, 2020 | A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a... |
| CVE-2020-6840 | CRITICAL | 9.8 | 1.5% | Jan 11, 2020 | In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c. |
| CVE-2020-6839 | CRITICAL | 9.8 | 1.4% | Jan 11, 2020 | In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c. |
| CVE-2020-6838 | CRITICAL | 9.8 | 1.5% | Jan 11, 2020 | In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c. |
| CVE-2020-6836 | CRITICAL | 9.8 | 2.1% | Jan 11, 2020 | grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injectio... |
| CVE-2020-6835 | CRITICAL | 9.8 | 2.0% | Jan 10, 2020 | An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking. |
| CVE-2020-6162 | CRITICAL | 9.1 | 1.7% | Jan 10, 2020 | An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitia... |
| CVE-2020-6756 | CRITICAL | 9.8 | 10.6% | Jan 9, 2020 | languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re... |
| CVE-2020-5510 | CRITICAL | 9.8 | 2.1% | Jan 8, 2020 | PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file. |
| CVE-2020-6170 | CRITICAL | 9.8 | 7.3% | Jan 8, 2020 | An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now