2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28501 | HIGH | 7.5 | 1.5% | Mar 22, 2021 | This affects the package es6-crawler-detect before 3.1.3. No limitation of user agent string length supplied to regex op... |
| CVE-2020-13963 | CRITICAL | 9.8 | 1.8% | Mar 21, 2021 | SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authenticati... |
| CVE-2020-27171 | MEDIUM | 6 | 0.6% | Mar 20, 2021 | An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resulta... |
| CVE-2020-27170 | MEDIUM | 4.7 | 0.6% | Mar 20, 2021 | An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds spec... |
| CVE-2020-4635 | MEDIUM | 5.3 | 0.9% | Mar 19, 2021 | IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames. |
| CVE-2020-25097 | HIGH | 8.6 | 8.2% | Mar 19, 2021 | An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trust... |
| CVE-2020-6578 | MEDIUM | 6.1 | 0.8% | Mar 19, 2021 | Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_... |
| CVE-2020-6577 | CRITICAL | 9.8 | 1.6% | Mar 19, 2021 | The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection. |
| CVE-2020-9367 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinvent... |
| CVE-2020-36144 | MEDIUM | 5.3 | 0.9% | Mar 18, 2021 | Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escapi... |
| CVE-2020-26886 | HIGH | 7.8 | 0.6% | Mar 18, 2021 | Softaculous before 5.5.7 is affected by a code execution vulnerability because of External Initialization of Trusted Var... |
| CVE-2020-26797 | HIGH | 7.5 | 4.2% | Mar 18, 2021 | Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_Channel... |
| CVE-2020-35492 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can pro... |
| CVE-2020-14516 | CRITICAL | 10 | 4.1% | Mar 18, 2021 | In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementa... |
| CVE-2020-27827 | HIGH | 7.5 | 3.2% | Mar 18, 2021 | A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when al... |
| CVE-2020-26155 | HIGH | 7.8 | 0.4% | Mar 18, 2021 | Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions fo... |
| CVE-2020-17457 | MEDIUM | 5.4 | 0.5% | Mar 17, 2021 | Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FI... |
| CVE-2020-35456 | MEDIUM | 5.5 | 0.5% | Mar 17, 2021 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and m... |
| CVE-2020-35455 | HIGH | 7.8 | 0.2% | Mar 17, 2021 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Sha... |
| CVE-2020-35454 | MEDIUM | 6.8 | 0.2% | Mar 17, 2021 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an ... |
| CVE-2020-14358 | — | — | — | Mar 17, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-8111 | — | — | — | Mar 17, 2021 | Rejected reason: Unused CVE for 2020 |
| CVE-2020-8106 | — | — | — | Mar 17, 2021 | Rejected reason: Unused CVE for 2020 |
| CVE-2020-28873 | HIGH | 7.5 | 0.9% | Mar 17, 2021 | Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user ... |
| CVE-2020-15766 | — | — | — | Mar 17, 2021 | Rejected reason: Unused CVE for 2020 |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now