2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11126 | CRITICAL | 9.1 | 0.8% | Jun 9, 2021 | Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, ... |
| CVE-2020-35442 | CRITICAL | 9.8 | 1.7% | Jun 2, 2021 | FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background v... |
| CVE-2020-35441 | CRITICAL | 9.8 | 1.1% | Jun 2, 2021 | FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.cl... |
| CVE-2020-4561 | CRITICAL | 10 | 2.9% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This a... |
| CVE-2020-10666 | CRITICAL | 9.8 | 2.2% | May 31, 2021 | The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote ... |
| CVE-2020-15782 | CRITICAL | 9.8 | 5.2% | May 28, 2021 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Co... |
| CVE-2020-27847 | CRITICAL | 9.8 | 1.7% | May 28, 2021 | A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validat... |
| CVE-2020-15180 | CRITICAL | 9 | 5.5% | May 27, 2021 | A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for co... |
| CVE-2020-12403 | CRITICAL | 9.1 | 1.5% | May 27, 2021 | A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chac... |
| CVE-2020-27832 | CRITICAL | 9 | 0.9% | May 27, 2021 | A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a r... |
| CVE-2020-13601 | CRITICAL | 9.8 | 0.9% | May 25, 2021 | Possible read out of bounds in dns read. Zephyr versions >= 1.14.2, >= 2.3.0 contain Out-of-bounds Read (CWE-125). For m... |
| CVE-2020-10064 | CRITICAL | 9.8 | 0.8% | May 25, 2021 | Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buff... |
| CVE-2020-20907 | CRITICAL | 9.1 | 2.2% | May 24, 2021 | MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/syst... |
| CVE-2020-28910 | CRITICAL | 9.8 | 3.9% | May 24, 2021 | Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalati... |
| CVE-2020-28908 | CRITICAL | 9.8 | 5.7% | May 24, 2021 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios. |
| CVE-2020-28907 | CRITICAL | 9.8 | 3.4% | May 24, 2021 | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Exec... |
| CVE-2020-28904 | CRITICAL | 9.8 | 3.6% | May 24, 2021 | Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via i... |
| CVE-2020-28902 | CRITICAL | 9.8 | 6.4% | May 24, 2021 | Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php. |
| CVE-2020-28901 | CRITICAL | 9.8 | 9.1% | May 24, 2021 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vecto... |
| CVE-2020-28900 | CRITICAL | 9.8 | 2.4% | May 24, 2021 | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows... |
| CVE-2020-25409 | CRITICAL | 9.8 | 1.6% | May 24, 2021 | Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. |
| CVE-2020-36331 | CRITICAL | 9.1 | 2.3% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The h... |
| CVE-2020-36330 | CRITICAL | 9.1 | 2.2% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. ... |
| CVE-2020-36329 | CRITICAL | 9.8 | 2.3% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early.... |
| CVE-2020-36328 | CRITICAL | 9.8 | 2.7% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is poss... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now