2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26905 | HIGH | 8.8 | 0.8% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26904 | HIGH | 8.8 | 0.7% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26903 | HIGH | 8.8 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26902 | HIGH | 8.8 | 2.2% | Oct 9, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2... |
| CVE-2020-26900 | HIGH | 8.8 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26898 | HIGH | 8.8 | 0.6% | Oct 9, 2020 | NETGEAR RAX40 devices before 1.0.3.80 are affected by incorrect configuration of security settings. |
| CVE-2020-26897 | HIGH | 8.8 | 0.6% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26522 | HIGH | 8.8 | 0.8% | Oct 9, 2020 | A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows... |
| CVE-2020-15838 | HIGH | 8.8 | 1.2% | Oct 9, 2020 | The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder h... |
| CVE-2020-26894 | HIGH | 7.8 | 0.4% | Oct 8, 2020 | LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in th... |
| CVE-2020-9048 | HIGH | 8.1 | 1.1% | Oct 8, 2020 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could a... |
| CVE-2020-26802 | HIGH | 8.8 | 0.6% | Oct 8, 2020 | forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=s... |
| CVE-2020-10816 | HIGH | 7.5 | 4.8% | Oct 8, 2020 | Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed ser... |
| CVE-2020-4799 | HIGH | 7.8 | 0.4% | Oct 8, 2020 | IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds wri... |
| CVE-2020-4280 | HIGH | 8.8 | 73.5% | Oct 8, 2020 | IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecur... |
| CVE-2020-13340 | HIGH | 8.7 | 68.6% | Oct 8, 2020 | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job ... |
| CVE-2020-2286 | HIGH | 8.8 | 1.3% | Oct 8, 2020 | Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when th... |
| CVE-2020-25263 | HIGH | 7.1 | 0.6% | Oct 8, 2020 | PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI:... |
| CVE-2020-3596 | HIGH | 7.5 | 1.2% | Oct 8, 2020 | A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communi... |
| CVE-2020-3544 | HIGH | 8.8 | 0.7% | Oct 8, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could... |
| CVE-2020-3535 | HIGH | 8.4 | 0.6% | Oct 8, 2020 | A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an aut... |
| CVE-2020-3467 | HIGH | 7.7 | 0.9% | Oct 8, 2020 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2020-7316 | HIGH | 7.8 | 0.4% | Oct 7, 2020 | Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local user... |
| CVE-2020-15176 | HIGH | 8.6 | 1.1% | Oct 7, 2020 | In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does no... |
| CVE-2020-26880 | HIGH | 7.8 | 0.3% | Oct 7, 2020 | Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now