2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36567 | HIGH | 7.5 | 1.4% | Dec 27, 2022 | Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbi... |
| CVE-2020-28191 | HIGH | 8.8 | 0.4% | Dec 26, 2022 | The console in Togglz before 2.9.4 allows CSRF. |
| CVE-2020-10650 | HIGH | 8.1 | 3.3% | Dec 26, 2022 | A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to pe... |
| CVE-2020-12069 | HIGH | 7.8 | 0.2% | Dec 26, 2022 | In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system sto... |
| CVE-2020-12067 | HIGH | 7.5 | 0.5% | Dec 26, 2022 | In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed b... |
| CVE-2020-36629 | HIGH | 7.5 | 0.8% | Dec 25, 2022 | A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpath... |
| CVE-2020-26302 | HIGH | 7.5 | 0.9% | Dec 22, 2022 | is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vuln... |
| CVE-2020-15685 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated wi... |
| CVE-2020-15679 | HIGH | 7.6 | 0.5% | Dec 22, 2022 | An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL,... |
| CVE-2020-36625 | HIGH | 8.8 | 0.3% | Dec 22, 2022 | A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocke... |
| CVE-2020-36620 | HIGH | 7.5 | 1.3% | Dec 21, 2022 | A vulnerability was found in Brondahl EnumStringValues up to 4.0.0. It has been declared as problematic. This vulnerabil... |
| CVE-2020-20588 | HIGH | 8.8 | 1.2% | Dec 15, 2022 | File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to... |
| CVE-2020-36610 | HIGH | 8 | 0.5% | Dec 8, 2022 | A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknow... |
| CVE-2020-23592 | HIGH | 8.8 | 0.5% | Nov 23, 2022 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenti... |
| CVE-2020-23585 | HIGH | 8.8 | 0.5% | Nov 23, 2022 | A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 ... |
| CVE-2020-12508 | HIGH | 7.5 | 0.8% | Nov 15, 2022 | In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path trave... |
| CVE-2020-12507 | HIGH | 8.8 | 0.7% | Nov 15, 2022 | In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL inj... |
| CVE-2020-12931 | HIGH | 7.8 | 0.3% | Nov 9, 2022 | Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their p... |
| CVE-2020-12930 | HIGH | 7.8 | 0.3% | Nov 9, 2022 | Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their priv... |
| CVE-2020-12509 | HIGH | 7.5 | 0.8% | Nov 7, 2022 | In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path trave... |
| CVE-2020-4099 | HIGH | 7.5 | 0.3% | Nov 1, 2022 | The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forge... |
| CVE-2020-12744 | HIGH | 7.8 | 0.2% | Oct 20, 2022 | The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during ... |
| CVE-2020-23648 | HIGH | 7.5 | 0.9% | Oct 19, 2022 | Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an... |
| CVE-2020-8976 | HIGH | 8.8 | 0.5% | Oct 17, 2022 | The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attac... |
| CVE-2020-8975 | HIGH | 7.5 | 1.0% | Oct 17, 2022 | ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web ap... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now