2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24949 | HIGH | 8.8 | 67.3% | Sep 3, 2020 | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr... |
| CVE-2020-7729 | HIGH | 7.1 | 2.4% | Sep 3, 2020 | The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load(... |
| CVE-2020-5420 | HIGH | 7.7 | 1.2% | Sep 3, 2020 | Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause de... |
| CVE-2020-5386 | HIGH | 7.5 | 1.3% | Sep 2, 2020 | Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker c... |
| CVE-2020-5369 | HIGH | 8.8 | 1.2% | Sep 2, 2020 | Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalat... |
| CVE-2020-7830 | HIGH | 7.8 | 0.8% | Sep 2, 2020 | RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lac... |
| CVE-2020-5779 | HIGH | 7.5 | 1.1% | Sep 2, 2020 | A flaw in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) relates to invalid parameter handling when calling strcpy_s... |
| CVE-2020-5778 | HIGH | 7.5 | 1.3% | Sep 2, 2020 | A flaw exists in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) due to improper validation of user-supplied data whe... |
| CVE-2020-25045 | HIGH | 7.8 | 0.4% | Sep 2, 2020 | Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were... |
| CVE-2020-25044 | HIGH | 7.1 | 0.3% | Sep 2, 2020 | Kaspersky Virus Removal Tool (KVRT) prior to 15.0.23.0 was vulnerable to arbitrary file corruption that could provide an... |
| CVE-2020-25043 | HIGH | 7.1 | 0.3% | Sep 2, 2020 | The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow... |
| CVE-2020-15167 | HIGH | 8.6 | 0.4% | Sep 2, 2020 | In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an... |
| CVE-2020-15094 | HIGH | 8.8 | 3.0% | Sep 2, 2020 | In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on... |
| CVE-2020-24028 | HIGH | 8.8 | 2.3% | Sep 2, 2020 | ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, passwor... |
| CVE-2020-23830 | HIGH | 7.1 | 0.5% | Sep 2, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 a... |
| CVE-2020-14209 | HIGH | 8.8 | 27.5% | Sep 2, 2020 | Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio... |
| CVE-2020-25079 | HIGH | 8.8 | 52.7% | Sep 2, 2020 | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.c... |
| CVE-2020-25078 | HIGH | 7.5 | 97.9% | Sep 2, 2020 | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate... |
| CVE-2020-16602 | HIGH | 8.1 | 6.0% | Sep 2, 2020 | Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra... |
| CVE-2020-5622 | HIGH | 7.5 | 1.3% | Sep 2, 2020 | Shadankun Server Security Type (excluding normal blocking method types) Ver.1.5.3 and earlier allows remote attackers to... |
| CVE-2020-24955 | HIGH | 7.8 | 0.9% | Sep 1, 2020 | SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivilege... |
| CVE-2020-6152 | HIGH | 7.8 | 1.9% | Sep 1, 2020 | A code execution vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.7. A spe... |
| CVE-2020-5776 | HIGH | 8.8 | 14.7% | Sep 1, 2020 | Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is poss... |
| CVE-2020-25070 | HIGH | 8.8 | 0.5% | Sep 1, 2020 | USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature. |
| CVE-2020-16208 | HIGH | 8.8 | 1.2% | Sep 1, 2020 | The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different config... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now