2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29164 | MEDIUM | 6.1 | 5.4% | Feb 3, 2021 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS). |
| CVE-2020-29163 | HIGH | 8.8 | 1.1% | Feb 3, 2021 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection. |
| CVE-2020-28144 | CRITICAL | 9.8 | 2.1% | Feb 3, 2021 | Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 ... |
| CVE-2020-35152 | HIGH | 7.8 | 0.3% | Feb 3, 2021 | Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process run... |
| CVE-2020-8672 | HIGH | 7.8 | 0.3% | Feb 2, 2021 | Out of bound read in BIOS firmware for 8th, 9th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 Series ... |
| CVE-2020-24490 | MEDIUM | 6.5 | 2.2% | Feb 2, 2021 | Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adja... |
| CVE-2020-8734 | MEDIUM | 6.7 | 0.3% | Feb 2, 2021 | Improper input validation in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privilege... |
| CVE-2020-4081 | MEDIUM | 6.1 | 0.6% | Feb 2, 2021 | In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS). |
| CVE-2020-29662 | MEDIUM | 5.3 | 0.7% | Feb 2, 2021 | In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path. |
| CVE-2020-1910 | HIGH | 7.8 | 5.1% | Feb 2, 2021 | A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13... |
| CVE-2020-14255 | HIGH | 7.5 | 1.1% | Feb 2, 2021 | HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties v... |
| CVE-2020-14221 | MEDIUM | 4.9 | 0.8% | Feb 2, 2021 | HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users. |
| CVE-2020-7775 | CRITICAL | 9.8 | 1.3% | Feb 2, 2021 | This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments... |
| CVE-2020-28498 | MEDIUM | 6.8 | 1.2% | Feb 2, 2021 | The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec... |
| CVE-2020-15097 | CRITICAL | 9.1 | 2.1% | Feb 2, 2021 | loklak is an open-source server application which is able to collect messages from various sources, including twitter. T... |
| CVE-2020-4934 | MEDIUM | 4.3 | 1.8% | Feb 2, 2021 | IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send... |
| CVE-2020-18568 | CRITICAL | 9.8 | 14.6% | Feb 2, 2021 | The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause ... |
| CVE-2020-25506 | CRITICAL | 9.8 | 100.0% | Feb 2, 2021 | D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead ... |
| CVE-2020-8101 | HIGH | 8.8 | 1.2% | Feb 2, 2021 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of A... |
| CVE-2020-28495 | HIGH | 7.3 | 3.6% | Feb 2, 2021 | This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to... |
| CVE-2020-28494 | HIGH | 8.6 | 1.7% | Feb 2, 2021 | This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type ... |
| CVE-2020-24335 | HIGH | 7.5 | 3.0% | Feb 2, 2021 | An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, ... |
| CVE-2020-1896 | CRITICAL | 9.8 | 2.4% | Feb 2, 2021 | A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7... |
| CVE-2020-25036 | HIGH | 8.8 | 2.0% | Feb 2, 2021 | UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, an... |
| CVE-2020-25035 | MEDIUM | 6.7 | 0.5% | Feb 2, 2021 | UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now