2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7079 | HIGH | 7.8 | 0.4% | Apr 17, 2020 | An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code executio... |
| CVE-2020-11877 | HIGH | 7.5 | 1.5% | Apr 17, 2020 | airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC e... |
| CVE-2020-11876 | HIGH | 7.5 | 1.7% | Apr 17, 2020 | airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of a... |
| CVE-2020-9523 | HIGH | 8.8 | 0.9% | Apr 17, 2020 | Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting ... |
| CVE-2020-4277 | HIGH | 7.5 | 1.4% | Apr 17, 2020 | IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an att... |
| CVE-2020-11875 | HIGH | 7.8 | 0.2% | Apr 17, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK ke... |
| CVE-2020-11874 | HIGH | 7.5 | 0.4% | Apr 17, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory ... |
| CVE-2020-11793 | HIGH | 8.8 | 2.8% | Apr 17, 2020 | A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allow... |
| CVE-2020-10947 | HIGH | 8.8 | 2.0% | Apr 17, 2020 | Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation. |
| CVE-2020-10813 | HIGH | 7.5 | 1.4% | Apr 17, 2020 | A buffer overflow vulnerability in FTPDMIN 0.96 allows attackers to crash the server via a crafted packet. |
| CVE-2020-11872 | HIGH | 7.5 | 0.7% | Apr 17, 2020 | The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests bef... |
| CVE-2020-11868 | HIGH | 7.5 | 2.1% | Apr 17, 2020 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronizatio... |
| CVE-2020-7486 | HIGH | 7.5 | 1.6% | Apr 16, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in... |
| CVE-2020-7484 | HIGH | 7.5 | 1.3% | Apr 16, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of servi... |
| CVE-2020-7483 | HIGH | 7.5 | 0.9% | Apr 16, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the '... |
| CVE-2020-7111 | HIGH | 7.2 | 1.9% | Apr 16, 2020 | A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Co... |
| CVE-2020-2180 | HIGH | 8.8 | 2.3% | Apr 16, 2020 | Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty... |
| CVE-2020-2179 | HIGH | 8.8 | 2.9% | Apr 16, 2020 | Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ... |
| CVE-2020-2178 | HIGH | 7.1 | 0.9% | Apr 16, 2020 | Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XX... |
| CVE-2020-11826 | HIGH | 7.5 | 0.5% | Apr 16, 2020 | Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. Ho... |
| CVE-2020-11825 | HIGH | 8.8 | 1.0% | Apr 16, 2020 | In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any use... |
| CVE-2020-11818 | HIGH | 8.8 | 0.8% | Apr 16, 2020 | In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed w... |
| CVE-2020-4347 | HIGH | 7.3 | 1.8% | Apr 16, 2020 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to ... |
| CVE-2020-3651 | HIGH | 7.5 | 0.7% | Apr 16, 2020 | Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames.... |
| CVE-2020-9280 | HIGH | 7.5 | 1.7% | Apr 15, 2020 | In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the de... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now