2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25050 | HIGH | 7.5 | 0.4% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The CMC service allows attackers to ... |
| CVE-2020-2075 | HIGH | 7.5 | 1.4% | Aug 31, 2020 | Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulksca... |
| CVE-2020-24354 | HIGH | 8.8 | 1.3% | Aug 31, 2020 | Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell... |
| CVE-2020-7527 | HIGH | 7.8 | 0.3% | Aug 31, 2020 | Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege ... |
| CVE-2020-7526 | HIGH | 8.8 | 2.3% | Aug 31, 2020 | Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could ... |
| CVE-2020-7525 | HIGH | 7.5 | 1.5% | Aug 31, 2020 | Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and... |
| CVE-2020-7524 | HIGH | 7.5 | 1.4% | Aug 31, 2020 | Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial ... |
| CVE-2020-7523 | HIGH | 7.8 | 0.2% | Aug 31, 2020 | Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification... |
| CVE-2020-24363 | HIGH | 8.8 | 20.7% | Aug 31, 2020 | TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP... |
| CVE-2020-20625 | HIGH | 7.5 | 1.7% | Aug 31, 2020 | Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated S... |
| CVE-2020-15687 | HIGH | 7.5 | 1.7% | Aug 31, 2020 | Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious ... |
| CVE-2020-13593 | HIGH | 8.8 | 0.3% | Aug 31, 2020 | The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R... |
| CVE-2020-11618 | HIGH | 7.8 | 0.4% | Aug 31, 2020 | THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start ... |
| CVE-2020-25032 | HIGH | 7.5 | 4.0% | Aug 31, 2020 | An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to... |
| CVE-2020-25031 | HIGH | 7.8 | 0.5% | Aug 31, 2020 | checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 execu... |
| CVE-2020-8097 | HIGH | 7.8 | 0.4% | Aug 30, 2020 | An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Sec... |
| CVE-2020-14352 | HIGH | 8 | 2.5% | Aug 30, 2020 | A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to ... |
| CVE-2020-7712 | HIGH | 7.2 | 3.7% | Aug 30, 2020 | This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function. |
| CVE-2020-24972 | HIGH | 8.8 | 4.7% | Aug 29, 2020 | The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code ... |
| CVE-2020-24897 | HIGH | 8.9 | 0.9% | Aug 29, 2020 | The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to... |
| CVE-2020-25019 | HIGH | 7.5 | 1.0% | Aug 29, 2020 | jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verify... |
| CVE-2020-3566 | HIGH | 8.6 | 4.0% | Aug 29, 2020 | A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow a... |
| CVE-2020-15159 | HIGH | 7.6 | 2.2% | Aug 28, 2020 | baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be execut... |
| CVE-2020-15155 | HIGH | 7.3 | 1.3% | Aug 28, 2020 | baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is req... |
| CVE-2020-15154 | HIGH | 7.3 | 1.0% | Aug 28, 2020 | baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is req... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now