2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16244 | HIGH | 7.2 | 0.7% | Sep 23, 2020 | GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible t... |
| CVE-2020-7122 | HIGH | 7.5 | 1.0% | Sep 23, 2020 | Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been ... |
| CVE-2020-7121 | HIGH | 7.5 | 1.0% | Sep 23, 2020 | Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been ... |
| CVE-2020-24625 | HIGH | 7.5 | 1.6% | Sep 23, 2020 | Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE P... |
| CVE-2020-24624 | HIGH | 7.5 | 1.6% | Sep 23, 2020 | Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE... |
| CVE-2020-14365 | HIGH | 7.1 | 0.2% | Sep 23, 2020 | A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, wh... |
| CVE-2020-10714 | HIGH | 7.5 | 1.5% | Sep 23, 2020 | A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with... |
| CVE-2020-25826 | HIGH | 7.8 | 0.4% | Sep 23, 2020 | PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSub... |
| CVE-2020-25821 | HIGH | 7.5 | 1.4% | Sep 23, 2020 | peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability onl... |
| CVE-2020-3569 | HIGH | 8.6 | 3.3% | Sep 23, 2020 | Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software coul... |
| CVE-2020-3143 | HIGH | 7.2 | 8.5% | Sep 23, 2020 | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TeleP... |
| CVE-2020-3135 | HIGH | 8.8 | 0.5% | Sep 23, 2020 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unaut... |
| CVE-2020-3133 | HIGH | 7.5 | 1.4% | Sep 23, 2020 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a... |
| CVE-2020-25515 | HIGH | 7.8 | 0.5% | Sep 22, 2020 | Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<s... |
| CVE-2020-25514 | HIGH | 8.4 | 0.6% | Sep 22, 2020 | Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://... |
| CVE-2020-14031 | HIGH | 7.2 | 1.6% | Sep 22, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be u... |
| CVE-2020-14028 | HIGH | 7.2 | 1.9% | Sep 22, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Auto... |
| CVE-2020-14026 | HIGH | 8.8 | 1.7% | Sep 22, 2020 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS ... |
| CVE-2020-14025 | HIGH | 8.8 | 0.5% | Sep 22, 2020 | Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a lin... |
| CVE-2020-14022 | HIGH | 8.8 | 1.8% | Sep 22, 2020 | Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contac... |
| CVE-2020-25487 | HIGH | 7.8 | 0.6% | Sep 22, 2020 | PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php... |
| CVE-2020-16202 | HIGH | 7.8 | 0.4% | Sep 22, 2020 | WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, whic... |
| CVE-2020-4622 | HIGH | 7.5 | 1.2% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it us... |
| CVE-2020-4621 | HIGH | 8.8 | 1.3% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due t... |
| CVE-2020-4620 | HIGH | 8.8 | 5.2% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now