2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27618 | MEDIUM | 5.5 | 0.9% | Feb 26, 2021 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input ... |
| CVE-2020-27223 | MEDIUM | 5.3 | 78.0% | Feb 26, 2021 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request contai... |
| CVE-2020-24686 | HIGH | 7.5 | 1.4% | Feb 26, 2021 | The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leadin... |
| CVE-2020-28646 | HIGH | 7.8 | 0.8% | Feb 26, 2021 | ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain dir... |
| CVE-2020-28199 | CRITICAL | 9.1 | 1.7% | Feb 26, 2021 | best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor. |
| CVE-2020-26200 | MEDIUM | 6.8 | 0.2% | Feb 26, 2021 | A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their... |
| CVE-2020-24455 | MEDIUM | 6.7 | 0.6% | Feb 26, 2021 | Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation ... |
| CVE-2020-17162 | HIGH | 8.8 | 2.2% | Feb 25, 2021 | Microsoft Windows Security Feature Bypass Vulnerability |
| CVE-2020-27543 | HIGH | 7.5 | 2.6% | Feb 25, 2021 | The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP... |
| CVE-2020-23534 | CRITICAL | 9.8 | 1.3% | Feb 25, 2021 | A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter. |
| CVE-2020-8032 | HIGH | 7 | 0.4% | Feb 25, 2021 | A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to esc... |
| CVE-2020-36254 | HIGH | 8.1 | 1.6% | Feb 25, 2021 | scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685. |
| CVE-2020-9053 | — | — | — | Feb 24, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2020-9052 | — | — | — | Feb 24, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2020-9051 | — | — | — | Feb 24, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2020-4931 | MEDIUM | 6.5 | 1.1% | Feb 24, 2021 | IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to ... |
| CVE-2020-11988 | HIGH | 8.2 | 6.7% | Feb 24, 2021 | Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input valida... |
| CVE-2020-11987 | HIGH | 8.2 | 13.6% | Feb 24, 2021 | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPan... |
| CVE-2020-7836 | HIGH | 7.8 | 0.6% | Feb 24, 2021 | VOICEYE WSActiveBridgeES versions prior to 2.1.0.3 contains a stack-based buffer overflow vulnerability caused by improp... |
| CVE-2020-27224 | CRITICAL | 9.6 | 2.4% | Feb 24, 2021 | In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute ... |
| CVE-2020-7846 | HIGH | 8.8 | 1.0% | Feb 24, 2021 | Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key.... |
| CVE-2020-28599 | HIGH | 7.8 | 2.0% | Feb 24, 2021 | A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-... |
| CVE-2020-12702 | MEDIUM | 4.6 | 0.3% | Feb 24, 2021 | Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS... |
| CVE-2020-8297 | MEDIUM | 4.3 | 1.3% | Feb 23, 2021 | Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users wit... |
| CVE-2020-7120 | MEDIUM | 5.3 | 0.3% | Feb 23, 2021 | A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now