2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26112 | HIGH | 7.5 | 0.9% | Sep 25, 2020 | The email quota cache in cPanel before 90.0.10 allows overwriting of files. |
| CVE-2020-26109 | HIGH | 7.5 | 1.2% | Sep 25, 2020 | cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557). |
| CVE-2020-26107 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561). |
| CVE-2020-26106 | HIGH | 7.5 | 1.3% | Sep 25, 2020 | cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558). |
| CVE-2020-26104 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552). |
| CVE-2020-26103 | HIGH | 7.5 | 1.3% | Sep 25, 2020 | In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551). |
| CVE-2020-26102 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550). |
| CVE-2020-26099 | HIGH | 7.5 | 1.2% | Sep 25, 2020 | cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491). |
| CVE-2020-25748 | HIGH | 8.1 | 0.8% | Sep 25, 2020 | A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, ... |
| CVE-2020-24718 | HIGH | 8.2 | 0.6% | Sep 25, 2020 | bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020... |
| CVE-2020-24692 | HIGH | 7.1 | 0.4% | Sep 25, 2020 | The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts... |
| CVE-2020-24621 | HIGH | 8.8 | 3.1% | Sep 25, 2020 | A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11... |
| CVE-2020-24593 | HIGH | 7.2 | 1.1% | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and acces... |
| CVE-2020-23837 | HIGH | 8.8 | 0.8% | Sep 25, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attacke... |
| CVE-2020-13387 | HIGH | 7.5 | 1.1% | Sep 25, 2020 | Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323. |
| CVE-2020-12824 | HIGH | 7.5 | 1.1% | Sep 25, 2020 | Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP. |
| CVE-2020-17365 | HIGH | 7.8 | 0.4% | Sep 24, 2020 | Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an aut... |
| CVE-2020-15843 | HIGH | 7.3 | 0.4% | Sep 24, 2020 | ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folde... |
| CVE-2020-13991 | HIGH | 7.5 | 2.5% | Sep 24, 2020 | vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register. |
| CVE-2020-8333 | HIGH | 7.8 | 0.3% | Sep 24, 2020 | A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStatio... |
| CVE-2020-15850 | HIGH | 7.8 | 0.5% | Sep 24, 2020 | Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access t... |
| CVE-2020-19447 | HIGH | 7.5 | 1.1% | Sep 24, 2020 | SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_file... |
| CVE-2020-3560 | HIGH | 8.6 | 1.4% | Sep 24, 2020 | A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial o... |
| CVE-2020-3559 | HIGH | 8.6 | 1.4% | Sep 24, 2020 | A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an ... |
| CVE-2020-3552 | HIGH | 7.4 | 0.5% | Sep 24, 2020 | A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthentic... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now