2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5351 | HIGH | 7.5 | 1.1% | Jul 28, 2021 | Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that... |
| CVE-2020-5341 | CRITICAL | 9.8 | 4.3% | Jul 28, 2021 | Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2... |
| CVE-2020-26180 | HIGH | 8.8 | 0.6% | Jul 28, 2021 | Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an ... |
| CVE-2020-18430 | HIGH | 7.5 | 1.3% | Jul 26, 2021 | tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to... |
| CVE-2020-18428 | HIGH | 7.5 | 1.2% | Jul 26, 2021 | tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to... |
| CVE-2020-23243 | MEDIUM | 4.8 | 0.5% | Jul 26, 2021 | Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature. |
| CVE-2020-23242 | MEDIUM | 4.8 | 0.5% | Jul 26, 2021 | Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature. |
| CVE-2020-23241 | MEDIUM | 4.8 | 0.5% | Jul 26, 2021 | Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature. |
| CVE-2020-23240 | MEDIUM | 4.8 | 0.5% | Jul 26, 2021 | Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature. |
| CVE-2020-23239 | MEDIUM | 4.8 | 0.5% | Jul 26, 2021 | Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature. |
| CVE-2020-23238 | MEDIUM | 5.4 | 0.5% | Jul 26, 2021 | Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature. |
| CVE-2020-23234 | MEDIUM | 4.8 | 0.6% | Jul 26, 2021 | Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed ... |
| CVE-2020-18174 | CRITICAL | 9.8 | 1.3% | Jul 26, 2021 | A process injection vulnerability in setup.exe of AutoHotkey 1.1.32.00 allows attackers to escalate privileges. |
| CVE-2020-18173 | HIGH | 7.8 | 0.5% | Jul 26, 2021 | A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code. |
| CVE-2020-18172 | CRITICAL | 9.8 | 1.3% | Jul 26, 2021 | A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate pr... |
| CVE-2020-18171 | HIGH | 8.8 | 0.4% | Jul 26, 2021 | TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed cr... |
| CVE-2020-18170 | CRITICAL | 9.8 | 1.3% | Jul 26, 2021 | An issue in the SeChangeNotifyPrivilege component of Abloy Key Manager Version 7.14301.0.0 allows attackers to escalate ... |
| CVE-2020-18169 | HIGH | 7.8 | 0.5% | Jul 26, 2021 | A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate ... |
| CVE-2020-17952 | CRITICAL | 9.8 | 2.5% | Jul 26, 2021 | A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbit... |
| CVE-2020-4623 | MEDIUM | 6.5 | 0.3% | Jul 26, 2021 | IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL ... |
| CVE-2020-12681 | HIGH | 7.5 | 0.5% | Jul 26, 2021 | Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/co... |
| CVE-2020-20741 | CRITICAL | 9.8 | 1.6% | Jul 23, 2021 | Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_T... |
| CVE-2020-14032 | CRITICAL | 9.8 | 2.1% | Jul 23, 2021 | ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM. |
| CVE-2020-22284 | HIGH | 7.5 | 1.2% | Jul 22, 2021 | A buffer overflow vulnerability in the zepif_linkoutput() function of Free Software Foundation lwIP git head version and... |
| CVE-2020-22283 | HIGH | 7.5 | 1.4% | Jul 22, 2021 | A buffer overflow vulnerability in the icmp6_send_response_with_addrs_and_netif() function of Free Software Foundation l... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now