2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7920 | HIGH | 7.5 | 2.1% | Feb 6, 2020 | pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service. |
| CVE-2020-5856 | HIGH | 7.5 | 1.0% | Feb 6, 2020 | On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' dr... |
| CVE-2020-8658 | HIGH | 8.8 | 9.9% | Feb 6, 2020 | The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_... |
| CVE-2020-8648 | HIGH | 7.1 | 0.7% | Feb 6, 2020 | There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in dr... |
| CVE-2020-8641 | HIGH | 8.8 | 10.8% | Feb 5, 2020 | Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php pa... |
| CVE-2020-3123 | HIGH | 7.5 | 2.6% | Feb 5, 2020 | A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.... |
| CVE-2020-3119 | HIGH | 8.8 | 5.1% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, ... |
| CVE-2020-3118 | HIGH | 8.8 | 11.8% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated,... |
| CVE-2020-3111 | HIGH | 8.8 | 3.1% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, ad... |
| CVE-2020-3110 | HIGH | 8.8 | 5.7% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras c... |
| CVE-2020-6833 | HIGH | 7.5 | 1.2% | Feb 5, 2020 | An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure... |
| CVE-2020-8507 | HIGH | 7.5 | 1.4% | Feb 5, 2020 | The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics. |
| CVE-2020-7978 | HIGH | 7.5 | 1.1% | Feb 5, 2020 | GitLab EE 12.6 and later through 12.7.2 allows Denial of Service. |
| CVE-2020-7972 | HIGH | 7.5 | 0.9% | Feb 5, 2020 | GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). |
| CVE-2020-7969 | HIGH | 7.5 | 1.2% | Feb 5, 2020 | GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure. |
| CVE-2020-7968 | HIGH | 7.5 | 1.1% | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. |
| CVE-2020-7966 | HIGH | 7.5 | 1.6% | Feb 5, 2020 | GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. |
| CVE-2020-7216 | HIGH | 7.5 | 1.1% | Feb 5, 2020 | An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial ... |
| CVE-2020-5237 | HIGH | 8.8 | 3.9% | Feb 5, 2020 | Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attack... |
| CVE-2020-5208 | HIGH | 8.8 | 3.3% | Feb 5, 2020 | It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a re... |
| CVE-2020-8517 | HIGH | 7.5 | 6.8% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials par... |
| CVE-2020-8450 | HIGH | 7.3 | 71.8% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer ove... |
| CVE-2020-8449 | HIGH | 7.5 | 8.3% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests ... |
| CVE-2020-8121 | HIGH | 8.1 | 1.0% | Feb 4, 2020 | A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer. |
| CVE-2020-8116 | HIGH | 7.3 | 3.1% | Feb 4, 2020 | Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now