2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10882 | HIGH | 8.8 | 44.4% | Mar 25, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch... |
| CVE-2020-9552 | HIGH | 7.8 | 5.6% | Mar 25, 2020 | Adobe Bridge versions 10.0 have a heap-based buffer overflow vulnerability. Successful exploitation could lead to arbitr... |
| CVE-2020-9551 | HIGH | 7.8 | 2.9% | Mar 25, 2020 | Adobe Bridge versions 10.0 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary co... |
| CVE-2020-3769 | HIGH | 7.5 | 2.9% | Mar 25, 2020 | Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful ex... |
| CVE-2020-3761 | HIGH | 7.5 | 4.1% | Mar 25, 2020 | ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a remote file read vulnerability. Successful exploitation ... |
| CVE-2020-5281 | HIGH | 7.5 | 1.3% | Mar 25, 2020 | In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from P... |
| CVE-2020-5280 | HIGH | 7.5 | 6.8% | Mar 25, 2020 | http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies... |
| CVE-2020-3806 | HIGH | 7.5 | 3.0% | Mar 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20... |
| CVE-2020-3804 | HIGH | 7.5 | 3.5% | Mar 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20... |
| CVE-2020-3803 | HIGH | 7.8 | 0.8% | Mar 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20... |
| CVE-2020-3802 | HIGH | 8.8 | 4.5% | Mar 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20... |
| CVE-2020-3800 | HIGH | 7.5 | 2.9% | Mar 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20... |
| CVE-2020-3766 | HIGH | 7.8 | 0.9% | Mar 25, 2020 | Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Succes... |
| CVE-2020-2171 | HIGH | 8.8 | 1.1% | Mar 25, 2020 | Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attack... |
| CVE-2020-2168 | HIGH | 8.8 | 2.0% | Mar 25, 2020 | Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation... |
| CVE-2020-2167 | HIGH | 8.8 | 2.1% | Mar 25, 2020 | Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of ... |
| CVE-2020-2166 | HIGH | 8.8 | 2.0% | Mar 25, 2020 | Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of a... |
| CVE-2020-2165 | HIGH | 7.5 | 1.1% | Mar 25, 2020 | Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins ... |
| CVE-2020-2160 | HIGH | 8.8 | 2.0% | Mar 25, 2020 | Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows att... |
| CVE-2020-10649 | HIGH | 7.8 | 0.6% | Mar 25, 2020 | DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code exec... |
| CVE-2020-9375 | HIGH | 7.5 | 28.2% | Mar 25, 2020 | TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a ... |
| CVE-2020-5558 | HIGH | 8.8 | 2.1% | Mar 25, 2020 | CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. |
| CVE-2020-8985 | HIGH | 8.8 | 0.5% | Mar 24, 2020 | ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality. |
| CVE-2020-8984 | HIGH | 7.5 | 0.5% | Mar 24, 2020 | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header. |
| CVE-2020-7001 | HIGH | 7.5 | 0.8% | Mar 24, 2020 | In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now