2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6424 | HIGH | 8.8 | 3.5% | Mar 23, 2020 | Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-6422 | HIGH | 8.8 | 2.4% | Mar 23, 2020 | Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-6420 | HIGH | 8.8 | 1.3% | Mar 23, 2020 | Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass sam... |
| CVE-2020-10364 | HIGH | 7.5 | 2.6% | Mar 23, 2020 | The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusa... |
| CVE-2020-10793 | HIGH | 8.8 | 1.9% | Mar 23, 2020 | CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the ... |
| CVE-2020-6650 | HIGH | 8.8 | 2.1% | Mar 23, 2020 | UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or ... |
| CVE-2020-10593 | HIGH | 7.5 | 2.3% | Mar 23, 2020 | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Servi... |
| CVE-2020-10592 | HIGH | 7.5 | 3.1% | Mar 23, 2020 | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Servi... |
| CVE-2020-10818 | HIGH | 7.2 | 2.9% | Mar 22, 2020 | Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the ... |
| CVE-2020-10808 | HIGH | 8.8 | 77.3% | Mar 22, 2020 | Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint.... |
| CVE-2020-10802 | HIGH | 8 | 2.1% | Mar 22, 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain par... |
| CVE-2020-10804 | HIGH | 8 | 2.7% | Mar 22, 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current... |
| CVE-2020-10800 | HIGH | 8.1 | 1.4% | Mar 21, 2020 | lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data... |
| CVE-2020-8882 | HIGH | 8.8 | 11.1% | Mar 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8881 | HIGH | 8.8 | 11.1% | Mar 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8880 | HIGH | 8.8 | 11.1% | Mar 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8878 | HIGH | 8.8 | 11.1% | Mar 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8136 | HIGH | 7.5 | 1.5% | Mar 20, 2020 | Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing ... |
| CVE-2020-8134 | HIGH | 8.1 | 1.2% | Mar 20, 2020 | Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external netw... |
| CVE-2020-9425 | HIGH | 7.5 | 16.7% | Mar 20, 2020 | An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved... |
| CVE-2020-10792 | HIGH | 7.5 | 1.9% | Mar 20, 2020 | openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placin... |
| CVE-2020-1864 | HIGH | 8.1 | 0.8% | Mar 20, 2020 | Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain som... |
| CVE-2020-1709 | HIGH | 7.8 | 0.3% | Mar 20, 2020 | A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulne... |
| CVE-2020-1707 | HIGH | 7 | 0.3% | Mar 20, 2020 | A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification ... |
| CVE-2020-10597 | HIGH | 7.1 | 0.8% | Mar 20, 2020 | Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Multiple out-of-bounds read vulnerabilities may be ex... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now