2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6971 | HIGH | 7.8 | 0.3% | Mar 5, 2020 | In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, ... |
| CVE-2020-5957 | HIGH | 7.8 | 0.3% | Mar 5, 2020 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which... |
| CVE-2020-9418 | HIGH | 7.8 | 0.4% | Mar 5, 2020 | An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attack... |
| CVE-2020-4278 | HIGH | 7.8 | 0.3% | Mar 5, 2020 | IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user... |
| CVE-2020-10174 | HIGH | 7 | 0.3% | Mar 5, 2020 | init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the pr... |
| CVE-2020-9544 | HIGH | 7.5 | 1.4% | Mar 5, 2020 | An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authenticat... |
| CVE-2020-9402 | HIGH | 8.8 | 22.5% | Mar 5, 2020 | Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a ... |
| CVE-2020-10173 | HIGH | 8.8 | 77.3% | Mar 5, 2020 | Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabiliti... |
| CVE-2020-10101 | HIGH | 7.5 | 1.1% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sen... |
| CVE-2020-10096 | HIGH | 7.5 | 1.1% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memor... |
| CVE-2020-8661 | HIGH | 7.5 | 1.8% | Mar 4, 2020 | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests. |
| CVE-2020-8659 | HIGH | 7.5 | 1.8% | Mar 4, 2020 | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many... |
| CVE-2020-7130 | HIGH | 7.5 | 2.2% | Mar 4, 2020 | HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard ... |
| CVE-2020-9476 | HIGH | 7.5 | 1.0% | Mar 4, 2020 | ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login... |
| CVE-2020-9372 | HIGH | 7.8 | 8.6% | Mar 4, 2020 | The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or ... |
| CVE-2020-3155 | HIGH | 7.4 | 0.9% | Mar 4, 2020 | A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, re... |
| CVE-2020-3148 | HIGH | 7.1 | 0.5% | Mar 4, 2020 | A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remot... |
| CVE-2020-3128 | HIGH | 7.8 | 1.9% | Mar 4, 2020 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros... |
| CVE-2020-3127 | HIGH | 7.8 | 2.3% | Mar 4, 2020 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros... |
| CVE-2020-10057 | HIGH | 8.8 | 0.9% | Mar 4, 2020 | GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an ... |
| CVE-2020-7988 | HIGH | 8.8 | 0.7% | Mar 4, 2020 | An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any u... |
| CVE-2020-5536 | HIGH | 8.8 | 0.6% | Mar 4, 2020 | OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentica... |
| CVE-2020-5535 | HIGH | 8.8 | 0.9% | Mar 4, 2020 | OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary... |
| CVE-2020-1734 | HIGH | 7.4 | 0.4% | Mar 3, 2020 | A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses s... |
| CVE-2020-5403 | HIGH | 7.5 | 1.1% | Mar 3, 2020 | Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now