2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7939 | HIGH | 8.8 | 1.2% | Jan 23, 2020 | SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. ... |
| CVE-2020-7938 | HIGH | 8.8 | 1.5% | Jan 23, 2020 | plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up t... |
| CVE-2020-7220 | HIGH | 7.5 | 1.4% | Jan 23, 2020 | HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount i... |
| CVE-2020-7931 | HIGH | 8.8 | 5.5% | Jan 23, 2020 | In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modif... |
| CVE-2020-5221 | HIGH | 7.2 | 1.2% | Jan 22, 2020 | In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple ... |
| CVE-2020-7595 | HIGH | 7.5 | 7.8% | Jan 21, 2020 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. |
| CVE-2020-7594 | HIGH | 7.2 | 2.5% | Jan 21, 2020 | MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitra... |
| CVE-2020-7040 | HIGH | 8.1 | 2.9% | Jan 21, 2020 | storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks tha... |
| CVE-2020-6638 | HIGH | 7.5 | 1.3% | Jan 21, 2020 | Grin through 2.1.1 has Insufficient Validation. |
| CVE-2020-6849 | HIGH | 8.8 | 1.3% | Jan 21, 2020 | The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with r... |
| CVE-2020-7213 | HIGH | 7.5 | 1.1% | Jan 21, 2020 | Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date... |
| CVE-2020-7211 | HIGH | 7.5 | 4.1% | Jan 21, 2020 | tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. |
| CVE-2020-7246 | HIGH | 8.8 | 83.2% | Jan 21, 2020 | A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code ... |
| CVE-2020-7244 | HIGH | 7.2 | 4.2% | Jan 20, 2020 | Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav... |
| CVE-2020-7243 | HIGH | 7.2 | 4.2% | Jan 20, 2020 | Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav... |
| CVE-2020-7242 | HIGH | 7.2 | 4.4% | Jan 20, 2020 | Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav... |
| CVE-2020-7241 | HIGH | 7.5 | 2.4% | Jan 20, 2020 | The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/... |
| CVE-2020-7240 | HIGH | 8.8 | 2.4% | Jan 20, 2020 | Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS ... |
| CVE-2020-7237 | HIGH | 8.8 | 36.8% | Jan 20, 2020 | Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug L... |
| CVE-2020-7232 | HIGH | 7.5 | 1.5% | Jan 19, 2020 | Evoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and passw... |
| CVE-2020-5398 | HIGH | 7.5 | 88.1% | Jan 17, 2020 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, ... |
| CVE-2020-7047 | HIGH | 8.8 | 2.5% | Jan 16, 2020 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal perm... |
| CVE-2020-7105 | HIGH | 7.5 | 2.8% | Jan 16, 2020 | async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return valu... |
| CVE-2020-7044 | HIGH | 7.5 | 3.2% | Jan 16, 2020 | In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c b... |
| CVE-2020-3941 | HIGH | 7 | 0.3% | Jan 15, 2020 | The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now