2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26876 | HIGH | 7.5 | 9.2% | Oct 7, 2020 | The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for cour... |
| CVE-2020-26596 | HIGH | 8.8 | 5.4% | Oct 7, 2020 | The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to exe... |
| CVE-2020-24246 | HIGH | 7.5 | 1.3% | Oct 7, 2020 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php... |
| CVE-2020-13334 | HIGH | 7.5 | 1.5% | Oct 7, 2020 | In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/gr... |
| CVE-2020-25985 | HIGH | 8.1 | 1.7% | Oct 7, 2020 | MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserv... |
| CVE-2020-7742 | HIGH | 7.5 | 1.5% | Oct 7, 2020 | This affects the package simpl-schema before 1.10.2. |
| CVE-2020-26606 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. An attacker can ac... |
| CVE-2020-26605 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attack... |
| CVE-2020-26604 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered in SystemUI on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Pendin... |
| CVE-2020-26602 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software.... |
| CVE-2020-26601 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered in DirEncryptService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Pendin... |
| CVE-2020-26600 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) software. Auto Hotspot allows attackers to obtain sensiti... |
| CVE-2020-26598 | HIGH | 7.5 | 0.3% | Oct 6, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management componen... |
| CVE-2020-26597 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software. The Wi-Fi subsystem has incorrect inpu... |
| CVE-2020-16267 | HIGH | 8.8 | 43.3% | Oct 6, 2020 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp r... |
| CVE-2020-15927 | HIGH | 8.8 | 40.3% | Oct 6, 2020 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp r... |
| CVE-2020-13343 | HIGH | 8.8 | 1.5% | Oct 6, 2020 | An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Pro... |
| CVE-2020-7740 | HIGH | 8.2 | 2.0% | Oct 6, 2020 | This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to t... |
| CVE-2020-24807 | HIGH | 7.8 | 2.0% | Oct 6, 2020 | The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remot... |
| CVE-2020-1906 | HIGH | 7.8 | 0.3% | Oct 6, 2020 | A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could h... |
| CVE-2020-1902 | HIGH | 7.5 | 0.7% | Oct 6, 2020 | A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or Whats... |
| CVE-2020-15174 | HIGH | 7.5 | 1.3% | Oct 6, 2020 | In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent nav... |
| CVE-2020-26582 | HIGH | 8.8 | 4.7% | Oct 6, 2020 | D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metachara... |
| CVE-2020-7739 | HIGH | 8.2 | 1.4% | Oct 6, 2020 | This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to... |
| CVE-2020-26575 | HIGH | 7.5 | 3.1% | Oct 6, 2020 | In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was add... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now