2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16268 | HIGH | 8.8 | 1.3% | Dec 29, 2020 | The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevate... |
| CVE-2020-35735 | MEDIUM | 4.7 | 0.7% | Dec 29, 2020 | Vidyo 02-09-/D allows clickjacking via the portal/ URI. |
| CVE-2020-9223 | HIGH | 7.5 | 0.9% | Dec 29, 2020 | There is a denial of service vulnerability in some Huawei smartphones. Due to the improper processing of received abnorm... |
| CVE-2020-9208 | MEDIUM | 6.5 | 0.6% | Dec 29, 2020 | There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authenticat... |
| CVE-2020-9207 | HIGH | 7.8 | 0.6% | Dec 29, 2020 | There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not veri... |
| CVE-2020-9125 | MEDIUM | 6.7 | 0.2% | Dec 29, 2020 | There is an out-of-bound read vulnerability in huawei smartphone Mate 30 versions earlier than 10.1.0.156 (C00E155R7P2).... |
| CVE-2020-9124 | HIGH | 7.5 | 0.9% | Dec 29, 2020 | There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker... |
| CVE-2020-9094 | HIGH | 7.5 | 0.7% | Dec 29, 2020 | There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with ... |
| CVE-2020-9093 | MEDIUM | 5.5 | 0.5% | Dec 29, 2020 | There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specif... |
| CVE-2020-35774 | MEDIUM | 5.4 | 87.4% | Dec 29, 2020 | server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configu... |
| CVE-2020-35773 | HIGH | 8.8 | 1.0% | Dec 29, 2020 | The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF. |
| CVE-2020-28283 | CRITICAL | 9.8 | 3.2% | Dec 29, 2020 | Prototype pollution vulnerability in 'libnested' versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of se... |
| CVE-2020-28282 | CRITICAL | 9.8 | 4.0% | Dec 29, 2020 | Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may l... |
| CVE-2020-28281 | CRITICAL | 9.8 | 3.6% | Dec 29, 2020 | Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denia... |
| CVE-2020-28280 | CRITICAL | 9.8 | 2.9% | Dec 29, 2020 | Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of se... |
| CVE-2020-28279 | CRITICAL | 9.8 | 3.0% | Dec 29, 2020 | Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of ... |
| CVE-2020-28278 | CRITICAL | 9.8 | 2.9% | Dec 29, 2020 | Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service... |
| CVE-2020-1848 | MEDIUM | 5.5 | 0.2% | Dec 29, 2020 | There is a resource management error vulnerability in Jackman-AL00D versions 8.2.0.185(C00R2P1). Local attackers constru... |
| CVE-2020-29471 | MEDIUM | 4.8 | 1.3% | Dec 29, 2020 | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as ... |
| CVE-2020-29470 | MEDIUM | 4.8 | 1.7% | Dec 29, 2020 | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an... |
| CVE-2020-28277 | CRITICAL | 9.8 | 2.9% | Dec 29, 2020 | Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service an... |
| CVE-2020-28276 | CRITICAL | 9.8 | 2.9% | Dec 29, 2020 | Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of servic... |
| CVE-2020-28275 | — | — | — | Dec 29, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-5807 | HIGH | 7.5 | 33.8% | Dec 29, 2020 | An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the Factor... |
| CVE-2020-5806 | MEDIUM | 5.5 | 4.8% | Dec 29, 2020 | An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseL... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now