2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0026 | HIGH | 7.8 | 0.2% | Feb 13, 2020 | In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to ... |
| CVE-2020-0022 | HIGH | 8.8 | 5.4% | Feb 13, 2020 | In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds cal... |
| CVE-2020-0015 | HIGH | 7.8 | 0.2% | Feb 13, 2020 | In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious... |
| CVE-2020-5239 | HIGH | 8.8 | 0.9% | Feb 13, 2020 | In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full a... |
| CVE-2020-1977 | HIGH | 8.8 | 0.5% | Feb 12, 2020 | Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated att... |
| CVE-2020-1975 | HIGH | 8.8 | 1.0% | Feb 12, 2020 | Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authentica... |
| CVE-2020-5399 | HIGH | 7.4 | 0.5% | Feb 12, 2020 | Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TL... |
| CVE-2020-8950 | HIGH | 7.8 | 1.0% | Feb 12, 2020 | The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of p... |
| CVE-2020-6192 | HIGH | 7.2 | 1.7% | Feb 12, 2020 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root ... |
| CVE-2020-6191 | HIGH | 7.2 | 1.6% | Feb 12, 2020 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with ro... |
| CVE-2020-6188 | HIGH | 8.8 | 0.7% | Feb 12, 2020 | VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700,... |
| CVE-2020-6186 | HIGH | 7.5 | 1.2% | Feb 12, 2020 | SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentica... |
| CVE-2020-8949 | HIGH | 8.8 | 2.8% | Feb 12, 2020 | Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572,... |
| CVE-2020-8947 | HIGH | 7.2 | 22.5% | Feb 12, 2020 | functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac... |
| CVE-2020-8946 | HIGH | 8.8 | 1.9% | Feb 12, 2020 | Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacter... |
| CVE-2020-8945 | HIGH | 7.5 | 5.1% | Feb 12, 2020 | The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container ... |
| CVE-2020-7046 | HIGH | 7.5 | 50.4% | Feb 12, 2020 | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command paramet... |
| CVE-2020-8815 | HIGH | 7.5 | 2.2% | Feb 12, 2020 | Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to ... |
| CVE-2020-8595 | HIGH | 7.3 | 2.6% | Feb 12, 2020 | Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. Th... |
| CVE-2020-2123 | HIGH | 8.8 | 2.3% | Feb 12, 2020 | Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary typ... |
| CVE-2020-2121 | HIGH | 8.8 | 2.7% | Feb 12, 2020 | Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiatio... |
| CVE-2020-2120 | HIGH | 8.8 | 1.1% | Feb 12, 2020 | Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2020-2116 | HIGH | 8.8 | 0.7% | Feb 12, 2020 | A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attack... |
| CVE-2020-2115 | HIGH | 8.8 | 1.1% | Feb 12, 2020 | Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2020-2114 | HIGH | 7.5 | 1.1% | Feb 12, 2020 | Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenk... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now