2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12468 | HIGH | 7.8 | 0.9% | Apr 29, 2020 | Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languag... |
| CVE-2020-11024 | HIGH | 8.2 | 0.8% | Apr 29, 2020 | In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack. The bug has been fi... |
| CVE-2020-12473 | HIGH | 7.2 | 1.4% | Apr 29, 2020 | MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting ... |
| CVE-2020-11021 | HIGH | 7.5 | 1.7% | Apr 29, 2020 | Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect doma... |
| CVE-2020-12461 | HIGH | 8.8 | 1.7% | Apr 29, 2020 | PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can d... |
| CVE-2020-8775 | HIGH | 8.9 | 0.8% | Apr 29, 2020 | Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags. |
| CVE-2020-8774 | HIGH | 8.8 | 0.8% | Apr 29, 2020 | Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID"... |
| CVE-2020-8773 | HIGH | 8.9 | 0.8% | Apr 29, 2020 | The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability. |
| CVE-2020-7804 | HIGH | 7.2 | 1.0% | Apr 29, 2020 | ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary ... |
| CVE-2020-2575 | HIGH | 7.5 | 0.7% | Apr 29, 2020 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar... |
| CVE-2020-12446 | HIGH | 7.8 | 0.5% | Apr 29, 2020 | The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memo... |
| CVE-2020-11677 | HIGH | 8.8 | 0.7% | Apr 29, 2020 | Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3). |
| CVE-2020-11676 | HIGH | 8.8 | 0.7% | Apr 29, 2020 | Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3). |
| CVE-2020-11675 | HIGH | 8.8 | 0.7% | Apr 29, 2020 | Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3). |
| CVE-2020-11674 | HIGH | 8.8 | 0.7% | Apr 29, 2020 | Cerner medico 26.00 allows variable reuse, possibly causing data corruption. |
| CVE-2020-11446 | HIGH | 7.8 | 0.4% | Apr 29, 2020 | ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard l... |
| CVE-2020-12246 | HIGH | 8.8 | 4.9% | Apr 29, 2020 | Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_... |
| CVE-2020-11884 | HIGH | 7 | 0.4% | Apr 29, 2020 | In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as de... |
| CVE-2020-12447 | HIGH | 7.5 | 11.8% | Apr 29, 2020 | A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users... |
| CVE-2020-8489 | HIGH | 7.8 | 0.3% | Apr 29, 2020 | Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all pub... |
| CVE-2020-8488 | HIGH | 7.8 | 0.4% | Apr 29, 2020 | Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published... |
| CVE-2020-8487 | HIGH | 7.8 | 0.3% | Apr 29, 2020 | Insufficient protection of the inter-process communication functions in ABB System 800xA Base (all published versions) e... |
| CVE-2020-8486 | HIGH | 7.8 | 0.3% | Apr 29, 2020 | Insufficient protection of the inter-process communication functions in ABB System 800xA RNRP (all published versions) e... |
| CVE-2020-8485 | HIGH | 7.8 | 0.3% | Apr 29, 2020 | Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published vers... |
| CVE-2020-8484 | HIGH | 7.8 | 0.3% | Apr 29, 2020 | Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now