2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17519 | HIGH | 7.5 | 97.9% | Jan 5, 2021 | A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file... |
| CVE-2020-17518 | HIGH | 7.5 | 52.3% | Jan 5, 2021 | Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the l... |
| CVE-2020-36158 | MEDIUM | 6.7 | 2.2% | Jan 5, 2021 | mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might ... |
| CVE-2020-5361 | HIGH | 7.6 | 0.4% | Jan 4, 2021 | Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist... |
| CVE-2020-29498 | MEDIUM | 6.1 | 1.1% | Jan 4, 2021 | Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attack... |
| CVE-2020-29497 | MEDIUM | 5.4 | 0.8% | Jan 4, 2021 | Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authentic... |
| CVE-2020-29496 | MEDIUM | 4.8 | 0.8% | Jan 4, 2021 | Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authentic... |
| CVE-2020-29492 | CRITICAL | 10 | 1.7% | Jan 4, 2021 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate... |
| CVE-2020-29491 | HIGH | 8.6 | 1.8% | Jan 4, 2021 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate... |
| CVE-2020-26297 | MEDIUM | 6.1 | 1.3% | Jan 4, 2021 | mdBook is a utility to create modern online books from Markdown files and is written in Rust. In mdBook before version 0... |
| CVE-2020-26294 | MEDIUM | 5.3 | 1.8% | Jan 4, 2021 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler ... |
| CVE-2020-26293 | MEDIUM | 6.1 | 1.0% | Jan 4, 2021 | HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. ... |
| CVE-2020-36157 | CRITICAL | 9.8 | 3.0% | Jan 4, 2021 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat... |
| CVE-2020-36156 | HIGH | 8.8 | 2.0% | Jan 4, 2021 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalatio... |
| CVE-2020-36155 | CRITICAL | 9.8 | 9.0% | Jan 4, 2021 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat... |
| CVE-2020-35219 | CRITICAL | 9.8 | 1.7% | Jan 4, 2021 | The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin passw... |
| CVE-2020-26292 | CRITICAL | 9.8 | 0.9% | Jan 4, 2021 | Creeper is an experimental dynamic, interpreted language. The binary release of Creeper Interpreter 1.1.3 contains poten... |
| CVE-2020-36154 | HIGH | 7.8 | 0.4% | Jan 4, 2021 | The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMD... |
| CVE-2020-25275 | HIGH | 7.5 | 4.7% | Jan 4, 2021 | Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafte... |
| CVE-2020-24386 | MEDIUM | 6.8 | 2.8% | Jan 4, 2021 | An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernatio... |
| CVE-2020-17537 | — | — | — | Jan 4, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2020-17536 | — | — | — | Jan 4, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2020-17535 | — | — | — | Jan 4, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2020-36112 | CRITICAL | 9.8 | 17.2% | Jan 4, 2021 | CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pub... |
| CVE-2020-35507 | MEDIUM | 5.5 | 1.2% | Jan 4, 2021 | There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now