2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8616 | HIGH | 8.6 | 10.6% | May 19, 2020 | A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when p... |
| CVE-2020-4411 | HIGH | 7.1 | 0.3% | May 19, 2020 | The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of... |
| CVE-2020-12663 | HIGH | 7.5 | 3.6% | May 19, 2020 | Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. |
| CVE-2020-12662 | HIGH | 7.5 | 3.2% | May 19, 2020 | Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered b... |
| CVE-2020-12244 | HIGH | 7.5 | 2.4% | May 19, 2020 | An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN respo... |
| CVE-2020-12667 | HIGH | 7.5 | 2.6% | May 19, 2020 | Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka... |
| CVE-2020-13149 | HIGH | 7.8 | 0.4% | May 18, 2020 | Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Mic... |
| CVE-2020-13146 | HIGH | 8.8 | 1.1% | May 18, 2020 | Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a ... |
| CVE-2020-13144 | HIGH | 8.8 | 11.0% | May 18, 2020 | Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne... |
| CVE-2020-6092 | HIGH | 7.8 | 42.3% | May 18, 2020 | An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially c... |
| CVE-2020-6074 | HIGH | 8.8 | 40.9% | May 18, 2020 | An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF do... |
| CVE-2020-13136 | HIGH | 7.5 | 1.2% | May 18, 2020 | D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer. |
| CVE-2020-11551 | HIGH | 8.8 | 1.7% | May 18, 2020 | An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel... |
| CVE-2020-11549 | HIGH | 8.8 | 4.1% | May 18, 2020 | An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel... |
| CVE-2020-12255 | HIGH | 8.8 | 52.6% | May 18, 2020 | rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor... |
| CVE-2020-12257 | HIGH | 8.8 | 1.4% | May 18, 2020 | rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such... |
| CVE-2020-10957 | HIGH | 7.5 | 7.2% | May 18, 2020 | In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dere... |
| CVE-2020-13129 | HIGH | 7.2 | 1.7% | May 18, 2020 | An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms... |
| CVE-2020-12858 | HIGH | 7.5 | 1.8% | May 18, 2020 | Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker... |
| CVE-2020-12857 | HIGH | 7.5 | 1.6% | May 18, 2020 | Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re... |
| CVE-2020-13128 | HIGH | 7.5 | 1.6% | May 18, 2020 | An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) acce... |
| CVE-2020-13111 | HIGH | 7.5 | 1.4% | May 16, 2020 | NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly valida... |
| CVE-2020-13110 | HIGH | 7.8 | 0.7% | May 16, 2020 | The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of ... |
| CVE-2020-12798 | HIGH | 7.8 | 0.3% | May 15, 2020 | Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command... |
| CVE-2020-1808 | HIGH | 7.1 | 0.5% | May 15, 2020 | Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions ea... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now