2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8818 | HIGH | 8.1 | 4.2% | Feb 25, 2020 | An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in t... |
| CVE-2020-9385 | HIGH | 7.5 | 1.6% | Feb 25, 2020 | A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upc... |
| CVE-2020-9381 | HIGH | 7.5 | 2.1% | Feb 24, 2020 | controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/w... |
| CVE-2020-1937 | HIGH | 8.8 | 2.7% | Feb 24, 2020 | Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run m... |
| CVE-2020-9369 | HIGH | 7.5 | 2.8% | Feb 24, 2020 | Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files,... |
| CVE-2020-5245 | HIGH | 8.8 | 2.8% | Feb 24, 2020 | Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privilege... |
| CVE-2020-5244 | HIGH | 7.5 | 1.9% | Feb 24, 2020 | In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Aut... |
| CVE-2020-9365 | HIGH | 7.5 | 6.9% | Feb 24, 2020 | An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function i... |
| CVE-2020-9363 | HIGH | 7.8 | 0.9% | Feb 24, 2020 | The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects End... |
| CVE-2020-9362 | HIGH | 7.8 | 1.5% | Feb 24, 2020 | The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. Th... |
| CVE-2020-8131 | HIGH | 7.5 | 5.0% | Feb 24, 2020 | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem a... |
| CVE-2020-5187 | HIGH | 8.8 | 2.4% | Feb 24, 2020 | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). |
| CVE-2020-9354 | HIGH | 7.5 | 1.2% | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functional... |
| CVE-2020-9353 | HIGH | 7.5 | 1.5% | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functional... |
| CVE-2020-9341 | HIGH | 8.8 | 0.6% | Feb 22, 2020 | CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&... |
| CVE-2020-9340 | HIGH | 7.2 | 1.0% | Feb 22, 2020 | fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter. |
| CVE-2020-8813 | HIGH | 8.8 | 73.8% | Feb 22, 2020 | graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a... |
| CVE-2020-8862 | HIGH | 8.8 | 13.3% | Feb 22, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-26... |
| CVE-2020-8861 | HIGH | 8.8 | 6.5% | Feb 22, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-13... |
| CVE-2020-8860 | HIGH | 8 | 0.7% | Feb 22, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Fir... |
| CVE-2020-9330 | HIGH | 8.8 | 1.1% | Feb 21, 2020 | Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind cred... |
| CVE-2020-9327 | HIGH | 7.5 | 3.7% | Feb 21, 2020 | In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault ... |
| CVE-2020-7907 | HIGH | 7.5 | 0.8% | Feb 21, 2020 | In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections. |
| CVE-2020-6842 | HIGH | 7.2 | 2.3% | Feb 21, 2020 | D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell... |
| CVE-2020-5534 | HIGH | 8 | 0.9% | Feb 21, 2020 | Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arb... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now