2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6013 | HIGH | 8.8 | 1.6% | Jul 6, 2020 | ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the ... |
| CVE-2020-5372 | HIGH | 7.5 | 0.9% | Jul 6, 2020 | Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to externa... |
| CVE-2020-5371 | HIGH | 8.8 | 1.2% | Jul 6, 2020 | Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulner... |
| CVE-2020-5368 | HIGH | 7.5 | 1.5% | Jul 6, 2020 | Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated ... |
| CVE-2020-5352 | HIGH | 8.8 | 2.9% | Jul 6, 2020 | Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated... |
| CVE-2020-14303 | HIGH | 7.5 | 3.5% | Jul 6, 2020 | A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba... |
| CVE-2020-15466 | HIGH | 7.5 | 3.1% | Jul 5, 2020 | In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/pa... |
| CVE-2020-15530 | HIGH | 7.8 | 0.5% | Jul 5, 2020 | An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM p... |
| CVE-2020-15529 | HIGH | 7.8 | 1.0% | Jul 5, 2020 | An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a g... |
| CVE-2020-15528 | HIGH | 7.8 | 1.3% | Jul 5, 2020 | An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or un... |
| CVE-2020-15523 | HIGH | 7.8 | 0.9% | Jul 4, 2020 | In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan hors... |
| CVE-2020-7284 | HIGH | 7.8 | 0.4% | Jul 3, 2020 | Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to ga... |
| CVE-2020-10281 | HIGH | 7.5 | 0.7% | Jul 3, 2020 | This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access ... |
| CVE-2020-7283 | HIGH | 8.8 | 0.6% | Jul 3, 2020 | Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edi... |
| CVE-2020-15518 | HIGH | 8.8 | 1.0% | Jul 3, 2020 | VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, w... |
| CVE-2020-8188 | HIGH | 8.8 | 1.3% | Jul 2, 2020 | We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and U... |
| CVE-2020-8163 | HIGH | 8.8 | 83.1% | Jul 2, 2020 | The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the... |
| CVE-2020-8161 | HIGH | 8.6 | 3.6% | Jul 2, 2020 | A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerabi... |
| CVE-2020-15082 | HIGH | 8.8 | 1.2% | Jul 2, 2020 | In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variable... |
| CVE-2020-2211 | HIGH | 8.8 | 2.3% | Jul 2, 2020 | Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the ins... |
| CVE-2020-12119 | HIGH | 8.1 | 0.5% | Jul 2, 2020 | Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value ... |
| CVE-2020-15503 | HIGH | 7.5 | 3.7% | Jul 2, 2020 | LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_im... |
| CVE-2020-5911 | HIGH | 7.3 | 1.0% | Jul 2, 2020 | In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packag... |
| CVE-2020-5910 | HIGH | 7.5 | 1.2% | Jul 2, 2020 | In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use ... |
| CVE-2020-15502 | HIGH | 7.5 | 1.5% | Jul 2, 2020 | The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web site... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now