2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8829 | HIGH | 8.8 | 0.5% | May 5, 2020 | CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis. |
| CVE-2020-7983 | HIGH | 8.1 | 0.6% | May 5, 2020 | A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF... |
| CVE-2020-12104 | HIGH | 8.8 | 1.6% | May 5, 2020 | The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via... |
| CVE-2020-12657 | HIGH | 7.8 | 0.7% | May 5, 2020 | An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bf... |
| CVE-2020-12653 | HIGH | 7.8 | 0.4% | May 5, 2020 | An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marv... |
| CVE-2020-12654 | HIGH | 7.1 | 1.2% | May 5, 2020 | An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wm... |
| CVE-2020-12649 | HIGH | 7.5 | 1.6% | May 5, 2020 | Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths. |
| CVE-2020-5343 | HIGH | 7.8 | 0.3% | May 4, 2020 | Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecu... |
| CVE-2020-5335 | HIGH | 8.8 | 0.5% | May 4, 2020 | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthentic... |
| CVE-2020-5332 | HIGH | 7.2 | 2.2% | May 4, 2020 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious us... |
| CVE-2020-10622 | HIGH | 7.8 | 0.8% | May 4, 2020 | LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorize... |
| CVE-2020-12642 | HIGH | 7.5 | 1.3% | May 4, 2020 | An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resulta... |
| CVE-2020-12109 | HIGH | 8.8 | 74.3% | May 4, 2020 | Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 ... |
| CVE-2020-12111 | HIGH | 8.8 | 8.0% | May 4, 2020 | Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304. |
| CVE-2020-11671 | HIGH | 8.1 | 1.1% | May 4, 2020 | Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid... |
| CVE-2020-11462 | HIGH | 7.5 | 1.3% | May 4, 2020 | An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interf... |
| CVE-2020-11443 | HIGH | 8.1 | 1.5% | May 4, 2020 | The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoo... |
| CVE-2020-10876 | HIGH | 7.5 | 1.1% | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its tim... |
| CVE-2020-10187 | HIGH | 7.5 | 2.0% | May 4, 2020 | Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve ... |
| CVE-2020-11842 | HIGH | 7.5 | 1.1% | May 4, 2020 | Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier... |
| CVE-2020-8018 | HIGH | 7.8 | 0.3% | May 4, 2020 | A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of ... |
| CVE-2020-7351 | HIGH | 8.8 | 65.2% | May 1, 2020 | An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allo... |
| CVE-2020-11028 | HIGH | 7.5 | 2.3% | Apr 30, 2020 | In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated discl... |
| CVE-2020-11027 | HIGH | 8.1 | 13.6% | Apr 30, 2020 | In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user passwo... |
| CVE-2020-11016 | HIGH | 8.8 | 2.3% | Apr 30, 2020 | IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled me... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now