2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9117 | HIGH | 7.8 | 0.2% | Dec 1, 2020 | HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5)... |
| CVE-2020-9114 | HIGH | 7.8 | 0.2% | Dec 1, 2020 | FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper p... |
| CVE-2020-9116 | HIGH | 7.2 | 1.0% | Dec 1, 2020 | Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker ... |
| CVE-2020-9115 | HIGH | 7.2 | 1.4% | Dec 1, 2020 | ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command... |
| CVE-2020-4129 | MEDIUM | 5.3 | 0.9% | Dec 1, 2020 | HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker coul... |
| CVE-2020-4126 | MEDIUM | 5.9 | 0.7% | Dec 1, 2020 | HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacke... |
| CVE-2020-14193 | MEDIUM | 5.4 | 0.8% | Nov 30, 2020 | Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache template... |
| CVE-2020-4127 | MEDIUM | 6.5 | 0.5% | Nov 30, 2020 | HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into ac... |
| CVE-2020-29441 | MEDIUM | 6.5 | 0.9% | Nov 30, 2020 | An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker c... |
| CVE-2020-29440 | MEDIUM | 4.6 | 0.2% | Nov 30, 2020 | Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob w... |
| CVE-2020-29439 | MEDIUM | 4.6 | 0.4% | Nov 30, 2020 | Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a ... |
| CVE-2020-29438 | MEDIUM | 6.5 | 0.4% | Nov 30, 2020 | Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This... |
| CVE-2020-16850 | HIGH | 7.5 | 2.1% | Nov 30, 2020 | Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by ... |
| CVE-2020-16849 | HIGH | 7.5 | 1.1% | Nov 30, 2020 | An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in... |
| CVE-2020-11867 | LOW | 3.3 | 0.5% | Nov 30, 2020 | Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary... |
| CVE-2020-29395 | MEDIUM | 6.1 | 11.7% | Nov 30, 2020 | The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. |
| CVE-2020-27587 | MEDIUM | 6.7 | 0.4% | Nov 30, 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vau... |
| CVE-2020-27586 | MEDIUM | 5.9 | 0.7% | Nov 30, 2020 | Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text. |
| CVE-2020-27585 | MEDIUM | 4.4 | 0.3% | Nov 30, 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings v... |
| CVE-2020-8351 | HIGH | 7.8 | 0.3% | Nov 30, 2020 | A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an a... |
| CVE-2020-6317 | LOW | 3.5 | 0.4% | Nov 30, 2020 | In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can acc... |
| CVE-2020-29394 | HIGH | 7.8 | 1.9% | Nov 30, 2020 | A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log ... |
| CVE-2020-17901 | MEDIUM | 6.5 | 0.4% | Nov 30, 2020 | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. |
| CVE-2020-29392 | MEDIUM | 4.6 | 0.4% | Nov 30, 2020 | The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical acce... |
| CVE-2020-29390 | CRITICAL | 9.8 | 36.7% | Nov 30, 2020 | Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that co... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now