2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12120 | HIGH | 7.5 | 1.8% | Apr 27, 2020 | The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such a... |
| CVE-2020-12273 | HIGH | 7.5 | 0.8% | Apr 27, 2020 | In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials. |
| CVE-2020-10996 | HIGH | 8.1 | 1.5% | Apr 27, 2020 | An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static tr... |
| CVE-2020-10664 | HIGH | 7.5 | 1.3% | Apr 27, 2020 | The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference. |
| CVE-2020-12254 | HIGH | 7.8 | 0.4% | Apr 26, 2020 | Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlin... |
| CVE-2020-12070 | HIGH | 7.5 | 2.0% | Apr 24, 2020 | The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulner... |
| CVE-2020-11004 | HIGH | 7.5 | 1.5% | Apr 24, 2020 | SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL quer... |
| CVE-2020-6828 | HIGH | 7.5 | 1.5% | Apr 24, 2020 | A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentia... |
| CVE-2020-6822 | HIGH | 8.8 | 1.3% | Apr 24, 2020 | On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecod... |
| CVE-2020-6821 | HIGH | 7.5 | 1.5% | Apr 24, 2020 | When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method,... |
| CVE-2020-6820 | HIGH | 8.1 | 6.3% | Apr 24, 2020 | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of t... |
| CVE-2020-6819 | HIGH | 8.1 | 3.0% | Apr 24, 2020 | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aw... |
| CVE-2020-5870 | HIGH | 8.1 | 0.5% | Apr 24, 2020 | In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for conne... |
| CVE-2020-12128 | HIGH | 7.5 | 1.6% | Apr 24, 2020 | DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path. |
| CVE-2020-12118 | HIGH | 8.2 | 1.4% | Apr 23, 2020 | The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parame... |
| CVE-2020-11012 | HIGH | 7.5 | 2.1% | Apr 23, 2020 | MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an ... |
| CVE-2020-5867 | HIGH | 8.1 | 0.4% | Apr 23, 2020 | In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check... |
| CVE-2020-5864 | HIGH | 7.4 | 1.0% | Apr 23, 2020 | In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS... |
| CVE-2020-12112 | HIGH | 7.5 | 5.3% | Apr 23, 2020 | BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion. |
| CVE-2020-4311 | HIGH | 7 | 0.3% | Apr 23, 2020 | IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially... |
| CVE-2020-4202 | HIGH | 8.8 | 1.0% | Apr 23, 2020 | IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the serv... |
| CVE-2020-11940 | HIGH | 7.5 | 1.3% | Apr 23, 2020 | In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positione... |
| CVE-2020-5571 | HIGH | 7.5 | 1.2% | Apr 23, 2020 | SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQU... |
| CVE-2020-12077 | HIGH | 8.8 | 5.6% | Apr 23, 2020 | The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions wi... |
| CVE-2020-12076 | HIGH | 8.8 | 0.7% | Apr 23, 2020 | The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now