2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7982 | HIGH | 8.1 | 1.6% | Mar 16, 2020 | An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the... |
| CVE-2020-7919 | HIGH | 7.5 | 2.6% | Mar 16, 2020 | Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 f... |
| CVE-2020-7248 | HIGH | 7.5 | 2.5% | Mar 16, 2020 | libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that... |
| CVE-2020-9471 | HIGH | 8.8 | 2.3% | Mar 16, 2020 | Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package... |
| CVE-2020-9321 | HIGH | 7.5 | 0.7% | Mar 16, 2020 | configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents f... |
| CVE-2020-6582 | HIGH | 7.5 | 3.9% | Mar 16, 2020 | Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a la... |
| CVE-2020-6581 | HIGH | 7.3 | 1.6% | Mar 16, 2020 | Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and ... |
| CVE-2020-5849 | HIGH | 7.5 | 93.2% | Mar 16, 2020 | Unraid 6.8.0 allows authentication bypass. |
| CVE-2020-5844 | HIGH | 7.2 | 30.3% | Mar 16, 2020 | index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t... |
| CVE-2020-3948 | HIGH | 7.8 | 0.3% | Mar 16, 2020 | Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privi... |
| CVE-2020-3947 | HIGH | 8.8 | 0.6% | Mar 16, 2020 | VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. ... |
| CVE-2020-6988 | HIGH | 7.5 | 3.9% | Mar 16, 2020 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont... |
| CVE-2020-6984 | HIGH | 7.5 | 2.8% | Mar 16, 2020 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont... |
| CVE-2020-6585 | HIGH | 8.8 | 1.2% | Mar 16, 2020 | Nagios Log Server 2.1.3 has CSRF. |
| CVE-2020-10241 | HIGH | 8.8 | 0.7% | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSR... |
| CVE-2020-10239 | HIGH | 8.8 | 2.7% | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows acc... |
| CVE-2020-10238 | HIGH | 7.5 | 5.6% | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading... |
| CVE-2020-10557 | HIGH | 8.8 | 1.4% | Mar 16, 2020 | An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged ... |
| CVE-2020-5546 | HIGH | 8.8 | 0.9% | Mar 16, 2020 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function include... |
| CVE-2020-9290 | HIGH | 7.8 | 0.6% | Mar 15, 2020 | An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attack... |
| CVE-2020-9287 | HIGH | 7.8 | 0.6% | Mar 15, 2020 | An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with ... |
| CVE-2020-10591 | HIGH | 7.5 | 2.0% | Mar 15, 2020 | An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potential... |
| CVE-2020-10589 | HIGH | 7.8 | 0.4% | Mar 15, 2020 | v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user... |
| CVE-2020-10588 | HIGH | 7.8 | 0.4% | Mar 15, 2020 | v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by... |
| CVE-2020-8141 | HIGH | 8.8 | 2.1% | Mar 15, 2020 | The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now