2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8558 | HIGH | 8.8 | 3.6% | Jul 27, 2020 | The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain ... |
| CVE-2020-1457 | HIGH | 7.8 | 12.3% | Jul 27, 2020 | A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory,... |
| CVE-2020-1425 | HIGH | 7.8 | 9.0% | Jul 27, 2020 | A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory... |
| CVE-2020-10609 | HIGH | 7.5 | 1.5% | Jul 27, 2020 | Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modif... |
| CVE-2020-15593 | HIGH | 7.8 | 0.4% | Jul 27, 2020 | SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Win... |
| CVE-2020-15592 | HIGH | 7.5 | 1.9% | Jul 27, 2020 | SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an exec... |
| CVE-2020-7694 | HIGH | 7.5 | 1.3% | Jul 27, 2020 | This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape se... |
| CVE-2020-5611 | HIGH | 8.8 | 1.2% | Jul 27, 2020 | Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attacker... |
| CVE-2020-15953 | HIGH | 7.4 | 2.4% | Jul 27, 2020 | LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affe... |
| CVE-2020-7687 | HIGH | 7.5 | 1.8% | Jul 25, 2020 | This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in ind... |
| CVE-2020-7686 | HIGH | 7.5 | 1.8% | Jul 25, 2020 | This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation insid... |
| CVE-2020-7683 | HIGH | 7.5 | 1.8% | Jul 25, 2020 | This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed... |
| CVE-2020-7682 | HIGH | 7.5 | 1.7% | Jul 25, 2020 | This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in i... |
| CVE-2020-7681 | HIGH | 7.5 | 1.7% | Jul 25, 2020 | This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in inde... |
| CVE-2020-10604 | HIGH | 7.5 | 2.1% | Jul 25, 2020 | In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager s... |
| CVE-2020-10610 | HIGH | 7.8 | 0.4% | Jul 24, 2020 | In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exp... |
| CVE-2020-10608 | HIGH | 7.8 | 0.2% | Jul 24, 2020 | In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity che... |
| CVE-2020-10606 | HIGH | 7.8 | 0.3% | Jul 24, 2020 | In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected ... |
| CVE-2020-10600 | HIGH | 7.1 | 0.8% | Jul 24, 2020 | An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. T... |
| CVE-2020-8207 | HIGH | 8.8 | 2.1% | Jul 24, 2020 | Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code exe... |
| CVE-2020-8174 | HIGH | 8.1 | 7.6% | Jul 24, 2020 | napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0. |
| CVE-2020-15932 | HIGH | 8.8 | 3.3% | Jul 24, 2020 | Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges. |
| CVE-2020-8326 | HIGH | 7.8 | 0.4% | Jul 24, 2020 | An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that cou... |
| CVE-2020-8317 | HIGH | 7.8 | 0.4% | Jul 24, 2020 | A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allo... |
| CVE-2020-15778 | HIGH | 7.4 | 13.0% | Jul 24, 2020 | scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick charac... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now