2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1706 | HIGH | 7 | 0.2% | Mar 9, 2020 | It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, ... |
| CVE-2020-10235 | HIGH | 8.8 | 1.7% | Mar 9, 2020 | An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have e... |
| CVE-2020-4217 | HIGH | 7.5 | 1.3% | Mar 9, 2020 | The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security vulnerability. An a... |
| CVE-2020-10223 | HIGH | 8.1 | 2.4% | Mar 8, 2020 | npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPD... |
| CVE-2020-10222 | HIGH | 8.1 | 2.4% | Mar 8, 2020 | npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted... |
| CVE-2020-10221 | HIGH | 8.8 | 36.8% | Mar 8, 2020 | lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands vi... |
| CVE-2020-9470 | HIGH | 7.8 | 0.6% | Mar 7, 2020 | An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session... |
| CVE-2020-10216 | HIGH | 8.8 | 5.6% | Mar 7, 2020 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands ... |
| CVE-2020-10215 | HIGH | 8.8 | 5.9% | Mar 7, 2020 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands ... |
| CVE-2020-10214 | HIGH | 8.8 | 18.3% | Mar 7, 2020 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary... |
| CVE-2020-10213 | HIGH | 8.8 | 5.0% | Mar 7, 2020 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands ... |
| CVE-2020-8635 | HIGH | 7.8 | 0.8% | Mar 7, 2020 | Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configura... |
| CVE-2020-8634 | HIGH | 7.8 | 0.4% | Mar 7, 2020 | Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file ma... |
| CVE-2020-10111 | HIGH | 7.5 | 1.9% | Mar 6, 2020 | Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the repor... |
| CVE-2020-7212 | HIGH | 7.5 | 3.3% | Mar 6, 2020 | The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denia... |
| CVE-2020-10193 | HIGH | 7.5 | 1.4% | Mar 6, 2020 | ESET Archive Support Module before 1294 allows virus-detection bypass via crafted RAR Compression Information in an arch... |
| CVE-2020-9458 | HIGH | 8.8 | 2.5% | Mar 6, 2020 | In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (wi... |
| CVE-2020-9457 | HIGH | 8.8 | 2.5% | Mar 6, 2020 | The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) t... |
| CVE-2020-9456 | HIGH | 8.8 | 2.5% | Mar 6, 2020 | In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (wi... |
| CVE-2020-9454 | HIGH | 8.8 | 1.1% | Mar 6, 2020 | A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requ... |
| CVE-2020-9531 | HIGH | 7.3 | 1.3% | Mar 6, 2020 | An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. In the Web resources of GetApps(com.xiaomi.mipicks), t... |
| CVE-2020-9756 | HIGH | 7.8 | 0.5% | Mar 6, 2020 | Patriot Viper RGB Driver 1.1 and prior exposes IOCTL and allows insufficient access control. The IOCTL Codes 0x80102050 ... |
| CVE-2020-10185 | HIGH | 8.6 | 1.5% | Mar 5, 2020 | The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is... |
| CVE-2020-10184 | HIGH | 7.5 | 1.5% | Mar 5, 2020 | The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remo... |
| CVE-2020-6986 | HIGH | 7.5 | 1.5% | Mar 5, 2020 | In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, ca... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now