2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25866 | HIGH | 7.5 | 3.9% | Oct 6, 2020 | In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a bu... |
| CVE-2020-25863 | HIGH | 7.5 | 4.9% | Oct 6, 2020 | In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was ad... |
| CVE-2020-25862 | HIGH | 7.5 | 2.4% | Oct 6, 2020 | In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in ... |
| CVE-2020-25803 | HIGH | 7.2 | 1.1% | Oct 6, 2020 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat... |
| CVE-2020-8781 | HIGH | 7.8 | 0.5% | Oct 6, 2020 | Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-pri... |
| CVE-2020-7466 | HIGH | 7.5 | 2.0% | Oct 6, 2020 | The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication m... |
| CVE-2020-25802 | HIGH | 7.2 | 1.1% | Oct 6, 2020 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat... |
| CVE-2020-25644 | HIGH | 7.5 | 2.2% | Oct 6, 2020 | A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It m... |
| CVE-2020-25643 | HIGH | 7.2 | 3.3% | Oct 6, 2020 | A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read ove... |
| CVE-2020-24219 | HIGH | 7.5 | 23.0% | Oct 6, 2020 | An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthentic... |
| CVE-2020-24216 | HIGH | 7.5 | 2.1% | Oct 6, 2020 | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrato... |
| CVE-2020-15598 | HIGH | 7.5 | 3.1% | Oct 6, 2020 | Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Tr... |
| CVE-2020-25987 | HIGH | 7.5 | 1.6% | Oct 6, 2020 | MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is b... |
| CVE-2020-25613 | HIGH | 7.5 | 3.8% | Oct 6, 2020 | An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP serv... |
| CVE-2020-5634 | HIGH | 8.8 | 0.6% | Oct 6, 2020 | ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-17... |
| CVE-2020-5632 | HIGH | 7.8 | 0.4% | Oct 6, 2020 | InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revisi... |
| CVE-2020-15235 | HIGH | 7.5 | 1.0% | Oct 5, 2020 | In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would norm... |
| CVE-2020-26048 | HIGH | 8.8 | 1.8% | Oct 5, 2020 | The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within... |
| CVE-2020-15236 | HIGH | 7.5 | 1.7% | Oct 5, 2020 | In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with... |
| CVE-2020-8182 | HIGH | 8 | 1.0% | Oct 5, 2020 | Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permiss... |
| CVE-2020-26061 | HIGH | 7.5 | 4.5% | Oct 5, 2020 | ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerabili... |
| CVE-2020-12302 | HIGH | 7.8 | 0.3% | Oct 5, 2020 | Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user... |
| CVE-2020-25636 | HIGH | 7.1 | 0.3% | Oct 5, 2020 | A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file t... |
| CVE-2020-7709 | HIGH | 7.2 | 1.8% | Oct 5, 2020 | This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported. |
| CVE-2020-25776 | HIGH | 7.8 | 0.6% | Oct 2, 2020 | Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an atta... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now