2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15147 | HIGH | 8.5 | 2.0% | Aug 21, 2020 | Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exp... |
| CVE-2020-24057 | HIGH | 8.8 | 5.5% | Aug 21, 2020 | The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows th... |
| CVE-2020-24056 | HIGH | 7.5 | 1.2% | Aug 21, 2020 | A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31,... |
| CVE-2020-24053 | HIGH | 7.5 | 1.2% | Aug 21, 2020 | Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidential... |
| CVE-2020-15309 | HIGH | 7 | 0.3% | Aug 21, 2020 | An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a ca... |
| CVE-2020-12457 | HIGH | 7.5 | 1.5% | Aug 21, 2020 | An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for... |
| CVE-2020-5774 | HIGH | 7.1 | 0.3% | Aug 21, 2020 | Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios... |
| CVE-2020-15070 | HIGH | 8.8 | 1.2% | Aug 21, 2020 | Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres... |
| CVE-2020-14215 | HIGH | 7.5 | 0.9% | Aug 21, 2020 | Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrato... |
| CVE-2020-24574 | HIGH | 7.8 | 0.6% | Aug 21, 2020 | The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local pri... |
| CVE-2020-24571 | HIGH | 7.5 | 18.0% | Aug 21, 2020 | NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal. |
| CVE-2020-24567 | HIGH | 7.8 | 0.6% | Aug 21, 2020 | voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file... |
| CVE-2020-24359 | HIGH | 7.5 | 1.0% | Aug 20, 2020 | HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet i... |
| CVE-2020-16282 | HIGH | 8.8 | 0.4% | Aug 20, 2020 | In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged... |
| CVE-2020-16281 | HIGH | 7.8 | 0.3% | Aug 20, 2020 | The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restri... |
| CVE-2020-10289 | HIGH | 8.8 | 1.9% | Aug 20, 2020 | Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YA... |
| CVE-2020-8870 | HIGH | 7.8 | 5.0% | Aug 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8869 | HIGH | 7.8 | 5.0% | Aug 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-15862 | HIGH | 7.8 | 0.4% | Aug 20, 2020 | Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability ... |
| CVE-2020-15861 | HIGH | 7.8 | 0.5% | Aug 20, 2020 | Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. |
| CVE-2020-15638 | HIGH | 7.8 | 6.1% | Aug 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.2... |
| CVE-2020-15635 | HIGH | 8.8 | 2.6% | Aug 20, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
| CVE-2020-15630 | HIGH | 7.8 | 4.9% | Aug 20, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P... |
| CVE-2020-15629 | HIGH | 7.8 | 6.3% | Aug 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-15531 | HIGH | 8.8 | 3.2% | Aug 20, 2020 | Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remot... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now