2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25647 | HIGH | 7.6 | 0.8% | Mar 3, 2021 | A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very li... |
| CVE-2020-25632 | HIGH | 8.2 | 1.2% | Mar 3, 2021 | A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a... |
| CVE-2020-14372 | HIGH | 7.5 | 1.7% | Mar 3, 2021 | A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Sec... |
| CVE-2020-13554 | HIGH | 7.8 | 0.5% | Mar 3, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD... |
| CVE-2020-35296 | HIGH | 7.5 | 2.2% | Mar 3, 2021 | ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboar... |
| CVE-2020-15937 | MEDIUM | 6.1 | 0.8% | Mar 3, 2021 | An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow... |
| CVE-2020-10519 | HIGH | 8.8 | 3.0% | Mar 3, 2021 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a... |
| CVE-2020-12530 | MEDIUM | 6.1 | 0.6% | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There ... |
| CVE-2020-12529 | MEDIUM | 5.3 | 0.8% | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There i... |
| CVE-2020-12528 | HIGH | 7.7 | 0.8% | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improp... |
| CVE-2020-12527 | MEDIUM | 6.5 | 1.0% | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all ve... |
| CVE-2020-28657 | CRITICAL | 9.8 | 1.7% | Mar 2, 2021 | In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL... |
| CVE-2020-4726 | LOW | 3.3 | 0.3% | Mar 2, 2021 | The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be r... |
| CVE-2020-4725 | LOW | 3.5 | 0.7% | Mar 2, 2021 | IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially cr... |
| CVE-2020-4719 | MEDIUM | 4.9 | 0.8% | Mar 2, 2021 | The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management ... |
| CVE-2020-23518 | MEDIUM | 5.4 | 2.0% | Mar 2, 2021 | Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to vers... |
| CVE-2020-25902 | MEDIUM | 6.1 | 0.7% | Mar 2, 2021 | Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execu... |
| CVE-2020-1936 | MEDIUM | 6.1 | 2.9% | Mar 2, 2021 | A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4. |
| CVE-2020-36240 | MEDIUM | 5.3 | 1.2% | Mar 1, 2021 | The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthe... |
| CVE-2020-9479 | MEDIUM | 5.5 | 2.0% | Mar 1, 2021 | When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory.... |
| CVE-2020-7929 | MEDIUM | 6.5 | 1.3% | Mar 1, 2021 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a... |
| CVE-2020-35662 | HIGH | 7.4 | 3.0% | Feb 27, 2021 | In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not alway... |
| CVE-2020-28972 | MEDIUM | 5.9 | 3.1% | Feb 27, 2021 | In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) do... |
| CVE-2020-28243 | HIGH | 7.8 | 4.3% | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection vi... |
| CVE-2020-36079 | HIGH | 7.2 | 4.7% | Feb 26, 2021 | Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacke... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now