2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1613 | HIGH | 7.5 | 1.3% | Apr 8, 2020 | A vulnerability in the BGP FlowSpec implementation may cause a Juniper Networks Junos OS device to terminate an establis... |
| CVE-2020-1991 | HIGH | 7.1 | 0.3% | Apr 8, 2020 | An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escala... |
| CVE-2020-1990 | HIGH | 7.2 | 2.1% | Apr 8, 2020 | A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to... |
| CVE-2020-1989 | HIGH | 7.8 | 0.3% | Apr 8, 2020 | An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global... |
| CVE-2020-1985 | HIGH | 7.8 | 0.3% | Apr 8, 2020 | Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite... |
| CVE-2020-1984 | HIGH | 7.8 | 0.3% | Apr 8, 2020 | Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create fol... |
| CVE-2020-10976 | HIGH | 7.5 | 1.2% | Apr 8, 2020 | GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget. |
| CVE-2020-11605 | HIGH | 7.5 | 0.4% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive informat... |
| CVE-2020-5735 | HIGH | 8.8 | 35.6% | Apr 8, 2020 | Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacke... |
| CVE-2020-5550 | HIGH | 8.1 | 1.9% | Apr 8, 2020 | Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows r... |
| CVE-2020-5549 | HIGH | 8.8 | 0.9% | Apr 8, 2020 | Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and ... |
| CVE-2020-11629 | HIGH | 7.2 | 0.6% | Apr 8, 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, whi... |
| CVE-2020-11627 | HIGH | 8.8 | 0.5% | Apr 8, 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has b... |
| CVE-2020-10366 | HIGH | 7.5 | 1.5% | Apr 8, 2020 | LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-... |
| CVE-2020-11620 | HIGH | 8.1 | 5.6% | Apr 7, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-11619 | HIGH | 8.1 | 3.6% | Apr 7, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-11612 | HIGH | 7.5 | 9.4% | Apr 7, 2020 | The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte st... |
| CVE-2020-11610 | HIGH | 8.8 | 1.4% | Apr 7, 2020 | An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js spec... |
| CVE-2020-11560 | HIGH | 7.8 | 1.0% | Apr 7, 2020 | NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. |
| CVE-2020-11561 | HIGH | 8.8 | 2.2% | Apr 7, 2020 | In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged fun... |
| CVE-2020-7615 | HIGH | 7.8 | 1.1% | Apr 7, 2020 | fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.... |
| CVE-2020-7613 | HIGH | 8.1 | 2.1% | Apr 7, 2020 | clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_... |
| CVE-2020-5734 | HIGH | 7.5 | 25.1% | Apr 7, 2020 | Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by... |
| CVE-2020-11587 | HIGH | 7.5 | 1.2% | Apr 6, 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request a... |
| CVE-2020-11599 | HIGH | 7.5 | 1.1% | Apr 6, 2020 | An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the us... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now