2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1940 | HIGH | 7.5 | 4.5% | Jan 28, 2020 | The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 a... |
| CVE-2020-7799 | HIGH | 7.2 | 19.8% | Jan 28, 2020 | An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Se... |
| CVE-2020-5523 | HIGH | 7.4 | 1.2% | Jan 28, 2020 | Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificat... |
| CVE-2020-7998 | HIGH | 8.8 | 1.5% | Jan 28, 2020 | An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerabili... |
| CVE-2020-5207 | HIGH | 7.5 | 0.8% | Jan 27, 2020 | In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and T... |
| CVE-2020-7952 | HIGH | 7.8 | 1.9% | Jan 27, 2020 | rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service ... |
| CVE-2020-7951 | HIGH | 7.8 | 1.9% | Jan 27, 2020 | meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by cr... |
| CVE-2020-7950 | HIGH | 7.8 | 1.9% | Jan 27, 2020 | meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by cr... |
| CVE-2020-7949 | HIGH | 7.8 | 4.2% | Jan 27, 2020 | schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by ... |
| CVE-2020-7238 | HIGH | 7.5 | 3.6% | Jan 27, 2020 | Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Tr... |
| CVE-2020-8009 | HIGH | 7.5 | 1.7% | Jan 27, 2020 | AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file. |
| CVE-2020-5522 | HIGH | 7.4 | 0.5% | Jan 27, 2020 | The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-... |
| CVE-2020-5521 | HIGH | 7.4 | 0.5% | Jan 27, 2020 | The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-t... |
| CVE-2020-5520 | HIGH | 7.4 | 0.5% | Jan 27, 2020 | The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-midd... |
| CVE-2020-7991 | HIGH | 8.8 | 3.1% | Jan 26, 2020 | Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. |
| CVE-2020-7984 | HIGH | 7.5 | 2.5% | Jan 26, 2020 | SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain ad... |
| CVE-2020-3142 | HIGH | 7.5 | 1.5% | Jan 26, 2020 | A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated... |
| CVE-2020-3115 | HIGH | 8.8 | 0.3% | Jan 26, 2020 | A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to... |
| CVE-2020-7596 | HIGH | 8.8 | 1.9% | Jan 25, 2020 | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. |
| CVE-2020-5224 | HIGH | 8.8 | 0.4% | Jan 24, 2020 | In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessio... |
| CVE-2020-6964 | HIGH | 8.6 | 1.4% | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center... |
| CVE-2020-5219 | HIGH | 8.8 | 2.4% | Jan 24, 2020 | Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userC... |
| CVE-2020-7226 | HIGH | 7.5 | 3.3% | Jan 24, 2020 | CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excess... |
| CVE-2020-6007 | HIGH | 7.9 | 2.1% | Jan 23, 2020 | Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handli... |
| CVE-2020-7940 | HIGH | 7.5 | 1.3% | Jan 23, 2020 | Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now