2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-22721 | HIGH | 7.8 | 0.5% | Aug 14, 2020 | A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary c... |
| CVE-2020-9228 | HIGH | 7.5 | 0.8% | Aug 14, 2020 | FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, ... |
| CVE-2020-17462 | HIGH | 7.8 | 1.0% | Aug 14, 2020 | CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a... |
| CVE-2020-16205 | HIGH | 7.2 | 60.4% | Aug 14, 2020 | Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code ... |
| CVE-2020-4662 | HIGH | 8.8 | 1.3% | Aug 14, 2020 | IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication v... |
| CVE-2020-7360 | HIGH | 7.3 | 0.5% | Aug 13, 2020 | An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before ... |
| CVE-2020-24346 | HIGH | 7.8 | 1.0% | Aug 13, 2020 | njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c. |
| CVE-2020-24345 | HIGH | 7.8 | 0.8% | Aug 13, 2020 | JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the ve... |
| CVE-2020-24344 | HIGH | 7.1 | 0.8% | Aug 13, 2020 | JerryScript through 2.3.0 has a (function({a=arguments}){const arguments}) buffer over-read. |
| CVE-2020-24343 | HIGH | 7.8 | 0.8% | Aug 13, 2020 | Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c. |
| CVE-2020-24342 | HIGH | 7.8 | 1.1% | Aug 13, 2020 | Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_ca... |
| CVE-2020-24331 | HIGH | 7.8 | 0.5% | Aug 13, 2020 | An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user sti... |
| CVE-2020-24330 | HIGH | 7.8 | 0.5% | Aug 13, 2020 | An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the... |
| CVE-2020-0261 | HIGH | 7.8 | 0.2% | Aug 13, 2020 | In C2 flame devices, there is a possible bypass of seccomp due to a missing configuration file. This could lead to local... |
| CVE-2020-15947 | HIGH | 8.8 | 1.1% | Aug 13, 2020 | A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows... |
| CVE-2020-15925 | HIGH | 8.8 | 1.1% | Aug 13, 2020 | A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers t... |
| CVE-2020-16087 | HIGH | 8.6 | 1.3% | Aug 13, 2020 | An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Win... |
| CVE-2020-8688 | HIGH | 7.5 | 1.5% | Aug 13, 2020 | Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potential... |
| CVE-2020-8687 | HIGH | 7.8 | 0.3% | Aug 13, 2020 | Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB... |
| CVE-2020-8681 | HIGH | 7.8 | 0.4% | Aug 13, 2020 | Out of bounds write in system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authen... |
| CVE-2020-8680 | HIGH | 7 | 0.2% | Aug 13, 2020 | Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potenti... |
| CVE-2020-12301 | HIGH | 8.2 | 0.3% | Aug 13, 2020 | Improper initialization in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a pri... |
| CVE-2020-12300 | HIGH | 8.2 | 0.3% | Aug 13, 2020 | Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may all... |
| CVE-2020-12299 | HIGH | 8.2 | 0.3% | Aug 13, 2020 | Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a p... |
| CVE-2020-0559 | HIGH | 7.8 | 0.3% | Aug 13, 2020 | Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now