2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8509 | HIGH | 7.5 | 10.4% | Mar 30, 2020 | Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading t... |
| CVE-2020-5527 | HIGH | 7.5 | 1.3% | Mar 30, 2020 | When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (al... |
| CVE-2020-5551 | HIGH | 8.8 | 1.4% | Mar 30, 2020 | Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a d... |
| CVE-2020-10940 | HIGH | 7.8 | 0.3% | Mar 27, 2020 | Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service. |
| CVE-2020-6095 | HIGH | 7.5 | 2.9% | Mar 27, 2020 | An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14... |
| CVE-2020-10939 | HIGH | 7.8 | 0.3% | Mar 27, 2020 | Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation. |
| CVE-2020-10954 | HIGH | 7.5 | 1.1% | Mar 27, 2020 | GitLab through 12.9 is affected by a potential DoS in repository archive download. |
| CVE-2020-10953 | HIGH | 7.5 | 1.4% | Mar 27, 2020 | In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue. |
| CVE-2020-10817 | HIGH | 8.8 | 1.8% | Mar 27, 2020 | The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress all... |
| CVE-2020-5863 | HIGH | 8.6 | 1.1% | Mar 27, 2020 | In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can c... |
| CVE-2020-5862 | HIGH | 7.5 | 1.1% | Mar 27, 2020 | On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop process... |
| CVE-2020-5861 | HIGH | 7.5 | 1.0% | Mar 27, 2020 | On BIG-IP 12.1.0-12.1.5, the TMM process may produce a core file in some cases when Ram Cache incorrectly optimizes stor... |
| CVE-2020-5860 | HIGH | 8.1 | 0.8% | Mar 27, 2020 | On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.... |
| CVE-2020-5859 | HIGH | 7.5 | 1.0% | Mar 27, 2020 | On BIG-IP 15.1.0.1, specially formatted HTTP/3 messages may cause TMM to produce a core file. |
| CVE-2020-5858 | HIGH | 7.8 | 0.5% | Mar 27, 2020 | On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-... |
| CVE-2020-5857 | HIGH | 7.5 | 1.0% | Mar 27, 2020 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, undisclosed HTTP behavior... |
| CVE-2020-10607 | HIGH | 8.8 | 2.1% | Mar 27, 2020 | In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper... |
| CVE-2020-1773 | HIGH | 8.1 | 1.5% | Mar 27, 2020 | An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or b... |
| CVE-2020-1772 | HIGH | 7.5 | 1.6% | Mar 27, 2020 | It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid... |
| CVE-2020-10508 | HIGH | 7.5 | 1.5% | Mar 27, 2020 | Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a spe... |
| CVE-2020-3921 | HIGH | 7.5 | 0.7% | Mar 27, 2020 | UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts informa... |
| CVE-2020-3920 | HIGH | 8.1 | 0.8% | Mar 27, 2020 | UltraLog Express device management interface does not properly perform access authentication in some specific pages/func... |
| CVE-2020-9521 | HIGH | 8.8 | 1.1% | Mar 26, 2020 | An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.0... |
| CVE-2020-9066 | HIGH | 7.8 | 0.6% | Mar 26, 2020 | Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vuln... |
| CVE-2020-7944 | HIGH | 7.7 | 0.9% | Mar 26, 2020 | In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now