2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7460 | HIGH | 7 | 0.7% | Aug 6, 2020 | In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 1... |
| CVE-2020-13365 | HIGH | 8.8 | 1.0% | Aug 6, 2020 | Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocu... |
| CVE-2020-13364 | HIGH | 8.8 | 1.2% | Aug 6, 2020 | A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, ... |
| CVE-2020-7361 | HIGH | 8.8 | 17.2% | Aug 6, 2020 | The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' co... |
| CVE-2020-7352 | HIGH | 8.8 | 3.8% | Aug 6, 2020 | The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to th... |
| CVE-2020-17366 | HIGH | 7.4 | 0.7% | Aug 5, 2020 | An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended acce... |
| CVE-2020-7298 | HIGH | 8.4 | 0.3% | Aug 5, 2020 | Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real tim... |
| CVE-2020-15127 | HIGH | 7.5 | 1.4% | Aug 5, 2020 | In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, ... |
| CVE-2020-13404 | HIGH | 8.8 | 6.5% | Aug 5, 2020 | The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection. |
| CVE-2020-15113 | HIGH | 7.1 | 0.2% | Aug 5, 2020 | In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory pa... |
| CVE-2020-4481 | HIGH | 8.2 | 2.0% | Aug 5, 2020 | IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE... |
| CVE-2020-16253 | HIGH | 8.1 | 0.5% | Aug 5, 2020 | The PgHero gem through 2.6.0 for Ruby allows CSRF. |
| CVE-2020-15135 | HIGH | 7.6 | 0.7% | Aug 4, 2020 | save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Token... |
| CVE-2020-15956 | HIGH | 7.5 | 10.5% | Aug 4, 2020 | ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer... |
| CVE-2020-15943 | HIGH | 8.1 | 1.8% | Aug 4, 2020 | An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possibl... |
| CVE-2020-13522 | HIGH | 7.1 | 0.5% | Aug 4, 2020 | An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially craf... |
| CVE-2020-16203 | HIGH | 7.8 | 1.9% | Aug 4, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited ... |
| CVE-2020-16199 | HIGH | 7.8 | 10.2% | Aug 4, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulne... |
| CVE-2020-16134 | HIGH | 8 | 0.8% | Aug 4, 2020 | An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet... |
| CVE-2020-7823 | HIGH | 7.8 | 1.2% | Aug 4, 2020 | DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandle... |
| CVE-2020-7822 | HIGH | 7.8 | 1.2% | Aug 4, 2020 | DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishand... |
| CVE-2020-6012 | HIGH | 7.4 | 0.5% | Aug 4, 2020 | ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sop... |
| CVE-2020-15467 | HIGH | 8.8 | 3.2% | Aug 4, 2020 | The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticat... |
| CVE-2020-5617 | HIGH | 7.8 | 0.3% | Aug 4, 2020 | Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unaut... |
| CVE-2020-5615 | HIGH | 8.8 | 0.7% | Aug 4, 2020 | Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now