2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14481 | HIGH | 7.8 | 0.2% | Feb 24, 2022 | The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticat... |
| CVE-2020-14478 | HIGH | 7.1 | 0.3% | Feb 24, 2022 | A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to ... |
| CVE-2020-10636 | HIGH | 7.5 | 0.3% | Feb 24, 2022 | Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obta... |
| CVE-2020-27467 | HIGH | 7.5 | 15.7% | Feb 24, 2022 | A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. |
| CVE-2020-8242 | HIGH | 7.2 | 0.9% | Feb 18, 2022 | Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user ne... |
| CVE-2020-25722 | HIGH | 8.8 | 1.6% | Feb 18, 2022 | Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker... |
| CVE-2020-25719 | HIGH | 7.2 | 1.7% | Feb 18, 2022 | A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authenticat... |
| CVE-2020-25718 | HIGH | 8.8 | 1.6% | Feb 18, 2022 | A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domai... |
| CVE-2020-25717 | HIGH | 8.1 | 1.6% | Feb 18, 2022 | A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cau... |
| CVE-2020-8107 | HIGH | 7.8 | 0.3% | Feb 18, 2022 | A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper... |
| CVE-2020-6922 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6921 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6919 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6918 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6917 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-13677 | HIGH | 7.5 | 1.0% | Feb 11, 2022 | Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which ma... |
| CVE-2020-13670 | HIGH | 7.5 | 1.1% | Feb 11, 2022 | Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadat... |
| CVE-2020-7534 | HIGH | 8.8 | 0.4% | Feb 4, 2022 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sen... |
| CVE-2020-12965 | HIGH | 7.5 | 2.4% | Feb 4, 2022 | When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using onl... |
| CVE-2020-12891 | HIGH | 7.8 | 0.3% | Feb 4, 2022 | AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop i... |
| CVE-2020-5953 | HIGH | 7.5 | 0.3% | Feb 3, 2022 | A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI h... |
| CVE-2020-28885 | HIGH | 7.2 | 2.1% | Jan 28, 2022 | Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje... |
| CVE-2020-28884 | HIGH | 7.2 | 2.0% | Jan 28, 2022 | Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje... |
| CVE-2020-4876 | HIGH | 8.2 | 1.7% | Jan 21, 2022 | IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2020-4875 | HIGH | 8.2 | 1.7% | Jan 21, 2022 | IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now