2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10787 | HIGH | 8.8 | 2.5% | Apr 21, 2020 | An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the... |
| CVE-2020-10786 | HIGH | 8.8 | 4.8% | Apr 21, 2020 | A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary co... |
| CVE-2020-1967 | HIGH | 7.5 | 53.3% | Apr 21, 2020 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due... |
| CVE-2020-11828 | HIGH | 7.5 | 1.2% | Apr 21, 2020 | In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger su... |
| CVE-2020-11968 | HIGH | 7.5 | 2.6% | Apr 21, 2020 | In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. N... |
| CVE-2020-11964 | HIGH | 7.5 | 2.2% | Apr 21, 2020 | In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the roo... |
| CVE-2020-11958 | HIGH | 7.8 | 1.7% | Apr 21, 2020 | re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme. |
| CVE-2020-9276 | HIGH | 8.8 | 2.6% | Apr 20, 2020 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests sup... |
| CVE-2020-11010 | HIGH | 8.8 | 1.0% | Apr 20, 2020 | In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when fi... |
| CVE-2020-11946 | HIGH | 7.5 | 51.8% | Apr 20, 2020 | Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. |
| CVE-2020-3946 | HIGH | 7.5 | 1.0% | Apr 20, 2020 | InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 ... |
| CVE-2020-11753 | HIGH | 8.8 | 1.7% | Apr 20, 2020 | An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user wi... |
| CVE-2020-5569 | HIGH | 8.4 | 0.3% | Apr 20, 2020 | An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is s... |
| CVE-2020-11886 | HIGH | 8.1 | 1.4% | Apr 17, 2020 | OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or s... |
| CVE-2020-11885 | HIGH | 7.2 | 0.8% | Apr 17, 2020 | WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the X... |
| CVE-2020-1751 | HIGH | 7 | 0.5% | Apr 17, 2020 | An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifi... |
| CVE-2020-0082 | HIGH | 7.8 | 0.4% | Apr 17, 2020 | In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe dese... |
| CVE-2020-0081 | HIGH | 7.8 | 0.2% | Apr 17, 2020 | In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local esc... |
| CVE-2020-0080 | HIGH | 7.8 | 0.5% | Apr 17, 2020 | In onOpActiveChanged and related methods of AppOpsControllerImpl.java, there is a possible way to display an app overlay... |
| CVE-2020-0079 | HIGH | 7.8 | 0.1% | Apr 17, 2020 | In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to loc... |
| CVE-2020-0078 | HIGH | 7.8 | 0.1% | Apr 17, 2020 | In releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This coul... |
| CVE-2020-7085 | HIGH | 7.8 | 1.4% | Apr 17, 2020 | A heap overflow vulnerability in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution o... |
| CVE-2020-7082 | HIGH | 8.8 | 2.0% | Apr 17, 2020 | A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a syste... |
| CVE-2020-7081 | HIGH | 8.8 | 1.5% | Apr 17, 2020 | A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write ... |
| CVE-2020-7080 | HIGH | 7.8 | 1.4% | Apr 17, 2020 | A buffer overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitrary code execution... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now