2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3530 | HIGH | 8.4 | 0.3% | Sep 4, 2020 | A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate... |
| CVE-2020-3495 | HIGH | 8.8 | 61.9% | Sep 4, 2020 | A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The... |
| CVE-2020-3478 | HIGH | 8.1 | 1.2% | Sep 4, 2020 | A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, re... |
| CVE-2020-3473 | HIGH | 7.8 | 0.4% | Sep 4, 2020 | A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate... |
| CVE-2020-3430 | HIGH | 8.8 | 3.9% | Sep 4, 2020 | A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated... |
| CVE-2020-24941 | HIGH | 7.5 | 1.1% | Sep 4, 2020 | An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some sit... |
| CVE-2020-24940 | HIGH | 7.5 | 1.2% | Sep 4, 2020 | An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in... |
| CVE-2020-24999 | HIGH | 7.8 | 1.1% | Sep 3, 2020 | There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by send... |
| CVE-2020-24996 | HIGH | 7.8 | 1.1% | Sep 3, 2020 | There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can ... |
| CVE-2020-1894 | HIGH | 8.8 | 1.8% | Sep 3, 2020 | A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, Whats... |
| CVE-2020-1890 | HIGH | 7.5 | 1.4% | Sep 3, 2020 | A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 coul... |
| CVE-2020-1886 | HIGH | 8.8 | 1.2% | Sep 3, 2020 | A buffer overflow in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could hav... |
| CVE-2020-25125 | HIGH | 7.8 | 1.3% | Sep 3, 2020 | GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other imp... |
| CVE-2020-11579 | HIGH | 7.5 | 26.5% | Sep 3, 2020 | An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation ... |
| CVE-2020-24162 | HIGH | 7.8 | 0.4% | Sep 3, 2020 | The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attack... |
| CVE-2020-24161 | HIGH | 7.8 | 0.4% | Sep 3, 2020 | Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerabi... |
| CVE-2020-24160 | HIGH | 7.8 | 0.5% | Sep 3, 2020 | Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers t... |
| CVE-2020-24159 | HIGH | 7.8 | 0.4% | Sep 3, 2020 | NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissi... |
| CVE-2020-24158 | HIGH | 7.8 | 0.3% | Sep 3, 2020 | 360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute maliciou... |
| CVE-2020-23811 | HIGH | 7.5 | 1.2% | Sep 3, 2020 | xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.jav... |
| CVE-2020-25068 | HIGH | 7.5 | 3.9% | Sep 3, 2020 | Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unau... |
| CVE-2020-25042 | HIGH | 7.2 | 18.1% | Sep 3, 2020 | An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authentic... |
| CVE-2020-24948 | HIGH | 7.2 | 13.1% | Sep 3, 2020 | The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimat... |
| CVE-2020-7381 | HIGH | 7.8 | 0.7% | Sep 3, 2020 | In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in t... |
| CVE-2020-4638 | HIGH | 7.2 | 1.7% | Sep 3, 2020 | IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now