2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15238 | HIGH | 7 | 4.5% | Oct 27, 2020 | Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-me... |
| CVE-2020-7755 | HIGH | 7.5 | 2.1% | Oct 27, 2020 | All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted ... |
| CVE-2020-11858 | HIGH | 7.8 | 2.7% | Oct 27, 2020 | Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Br... |
| CVE-2020-7754 | HIGH | 7.5 | 3.4% | Oct 27, 2020 | This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer ... |
| CVE-2020-23945 | HIGH | 7.5 | 1.2% | Oct 27, 2020 | A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter... |
| CVE-2020-8579 | HIGH | 7.5 | 1.3% | Oct 27, 2020 | Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access ... |
| CVE-2020-6023 | HIGH | 7.8 | 0.3% | Oct 27, 2020 | Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in... |
| CVE-2020-23864 | HIGH | 7.8 | 0.5% | Oct 27, 2020 | An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a mali... |
| CVE-2020-7753 | HIGH | 7.5 | 3.7% | Oct 27, 2020 | All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim(). |
| CVE-2020-27180 | HIGH | 7.5 | 1.2% | Oct 27, 2020 | konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter. |
| CVE-2020-15352 | HIGH | 7.2 | 3.2% | Oct 27, 2020 | An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) befo... |
| CVE-2020-1915 | HIGH | 7.5 | 1.6% | Oct 26, 2020 | An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c7... |
| CVE-2020-26878 | HIGH | 8.8 | 11.5% | Oct 26, 2020 | Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (... |
| CVE-2020-26566 | HIGH | 7.5 | 4.4% | Oct 26, 2020 | A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a ... |
| CVE-2020-15271 | HIGH | 8.8 | 2.0% | Oct 26, 2020 | In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and ... |
| CVE-2020-7752 | HIGH | 8.8 | 5.7% | Oct 26, 2020 | This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker... |
| CVE-2020-27187 | HIGH | 7.8 | 0.4% | Oct 26, 2020 | An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic... |
| CVE-2020-7125 | HIGH | 8.8 | 1.4% | Oct 26, 2020 | A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
| CVE-2020-24632 | HIGH | 7.2 | 2.6% | Oct 26, 2020 | A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.... |
| CVE-2020-24631 | HIGH | 7.2 | 2.6% | Oct 26, 2020 | A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3... |
| CVE-2020-15897 | HIGH | 7.5 | 1.3% | Oct 26, 2020 | Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attack... |
| CVE-2020-13100 | HIGH | 7.5 | 1.3% | Oct 26, 2020 | Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x bef... |
| CVE-2020-7751 | HIGH | 7.2 | 1.5% | Oct 26, 2020 | pathval before version 1.1.1 is vulnerable to prototype pollution. |
| CVE-2020-24848 | HIGH | 7.8 | 0.4% | Oct 23, 2020 | FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform ... |
| CVE-2020-5990 | HIGH | 7.8 | 0.4% | Oct 23, 2020 | NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which m... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now