2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10682 | HIGH | 7.8 | 1.9% | Mar 20, 2020 | The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1... |
| CVE-2020-10669 | HIGH | 7.5 | 3.5% | Mar 19, 2020 | The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the... |
| CVE-2020-7006 | HIGH | 8.4 | 1.7% | Mar 19, 2020 | Systech Corporation NDS-5000 Terminal Server, NDS/5008 (8 Port, RJ45), firmware Version 02D.30. Successful exploitation ... |
| CVE-2020-10671 | HIGH | 8.8 | 0.7% | Mar 19, 2020 | The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-... |
| CVE-2020-3266 | HIGH | 7.8 | 0.6% | Mar 19, 2020 | A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbi... |
| CVE-2020-3265 | HIGH | 7.8 | 0.4% | Mar 19, 2020 | A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to ... |
| CVE-2020-3264 | HIGH | 7.1 | 0.7% | Mar 19, 2020 | A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflo... |
| CVE-2020-1705 | HIGH | 7 | 0.3% | Mar 19, 2020 | A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an i... |
| CVE-2020-10678 | HIGH | 8.8 | 1.0% | Mar 19, 2020 | In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an... |
| CVE-2020-10675 | HIGH | 7.5 | 2.5% | Mar 19, 2020 | The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via... |
| CVE-2020-10648 | HIGH | 7.8 | 1.3% | Mar 19, 2020 | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images ... |
| CVE-2020-10673 | HIGH | 8.8 | 8.0% | Mar 18, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-10672 | HIGH | 8.8 | 3.0% | Mar 18, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-9326 | HIGH | 7.5 | 1.0% | Mar 18, 2020 | BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 ... |
| CVE-2020-9325 | HIGH | 7.5 | 1.8% | Mar 18, 2020 | Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download. |
| CVE-2020-9324 | HIGH | 7.5 | 1.4% | Mar 18, 2020 | Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC. |
| CVE-2020-7002 | HIGH | 7.8 | 1.1% | Mar 18, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be explo... |
| CVE-2020-8470 | HIGH | 7.5 | 4.5% | Mar 18, 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl... |
| CVE-2020-8468 | HIGH | 8.8 | 5.8% | Mar 18, 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a co... |
| CVE-2020-8467 | HIGH | 8.8 | 10.8% | Mar 18, 2020 | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow r... |
| CVE-2020-3950 | HIGH | 7.8 | 7.3% | Mar 17, 2020 | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for ... |
| CVE-2020-10120 | HIGH | 7.2 | 2.7% | Mar 17, 2020 | cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545). |
| CVE-2020-10115 | HIGH | 7.2 | 1.8% | Mar 17, 2020 | cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). |
| CVE-2020-9346 | HIGH | 8.8 | 2.5% | Mar 16, 2020 | Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attack... |
| CVE-2020-8787 | HIGH | 7.5 | 0.9% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submit... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now