2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6060 | HIGH | 7.5 | 2.2% | Feb 4, 2020 | A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially ... |
| CVE-2020-6059 | HIGH | 8.2 | 2.6% | Feb 4, 2020 | An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A ... |
| CVE-2020-7221 | HIGH | 7.8 | 0.7% | Feb 4, 2020 | mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root becau... |
| CVE-2020-4163 | HIGH | 7.2 | 1.6% | Feb 4, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user... |
| CVE-2020-3938 | HIGH | 7.5 | 1.5% | Feb 4, 2020 | SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to laun... |
| CVE-2020-3937 | HIGH | 7.5 | 1.4% | Feb 4, 2020 | SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries ... |
| CVE-2020-8545 | HIGH | 7.5 | 1.3% | Feb 3, 2020 | Global.py in AIL framework 2.8 allows path traversal. |
| CVE-2020-3927 | HIGH | 7.5 | 1.2% | Feb 3, 2020 | An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific ... |
| CVE-2020-3926 | HIGH | 7.5 | 1.5% | Feb 3, 2020 | An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific ... |
| CVE-2020-3925 | HIGH | 8.8 | 2.8% | Feb 3, 2020 | A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long ... |
| CVE-2020-7914 | HIGH | 7.5 | 1.9% | Jan 31, 2020 | In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over t... |
| CVE-2020-7219 | HIGH | 7.5 | 2.0% | Jan 31, 2020 | HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were suscepti... |
| CVE-2020-7218 | HIGH | 7.5 | 1.5% | Jan 31, 2020 | HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptib... |
| CVE-2020-5232 | HIGH | 8.7 | 1.2% | Jan 31, 2020 | A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ... |
| CVE-2020-8495 | HIGH | 7.5 | 3.1% | Jan 30, 2020 | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se... |
| CVE-2020-8494 | HIGH | 8.8 | 1.1% | Jan 30, 2020 | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser se... |
| CVE-2020-5230 | HIGH | 7.5 | 1.2% | Jan 30, 2020 | Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be ... |
| CVE-2020-5222 | HIGH | 8.8 | 0.9% | Jan 30, 2020 | Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an add... |
| CVE-2020-5229 | HIGH | 8.1 | 0.6% | Jan 30, 2020 | Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthe... |
| CVE-2020-5228 | HIGH | 7.5 | 1.0% | Jan 30, 2020 | Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH ... |
| CVE-2020-8093 | HIGH | 7.8 | 0.4% | Jan 30, 2020 | A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a li... |
| CVE-2020-3147 | HIGH | 7.5 | 2.3% | Jan 30, 2020 | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause ... |
| CVE-2020-7909 | HIGH | 7.5 | 1.1% | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI. |
| CVE-2020-7906 | HIGH | 7.5 | 0.7% | Jan 30, 2020 | In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows instal... |
| CVE-2020-7905 | HIGH | 7.5 | 1.2% | Jan 30, 2020 | Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now