2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23653 | CRITICAL | 9.8 | 4.1% | Jan 13, 2021 | An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/... |
| CVE-2020-5685 | CRITICAL | 9.8 | 1.8% | Jan 13, 2021 | UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands ... |
| CVE-2020-5633 | CRITICAL | 9.8 | 3.2% | Jan 13, 2021 | Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen... |
| CVE-2020-25226 | CRITICAL | 9.8 | 1.9% | Jan 12, 2021 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),... |
| CVE-2020-15800 | CRITICAL | 9.8 | 1.7% | Jan 12, 2021 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),... |
| CVE-2020-35458 | CRITICAL | 9.8 | 5.3% | Jan 12, 2021 | An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk... |
| CVE-2020-26712 | CRITICAL | 9.8 | 2.1% | Jan 12, 2021 | REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses t... |
| CVE-2020-14275 | CRITICAL | 9.8 | 1.4% | Jan 12, 2021 | Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could al... |
| CVE-2020-27637 | CRITICAL | 9.8 | 2.2% | Jan 12, 2021 | The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to... |
| CVE-2020-0471 | CRITICAL | 9.8 | 1.6% | Jan 11, 2021 | In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetoot... |
| CVE-2020-24027 | CRITICAL | 9.8 | 1.6% | Jan 11, 2021 | In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling o... |
| CVE-2020-11995 | CRITICAL | 9.8 | 5.8% | Jan 11, 2021 | A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code exec... |
| CVE-2020-35205 | CRITICAL | 9.8 | 1.9% | Jan 11, 2021 | Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attacker... |
| CVE-2020-16025 | CRITICAL | 9.6 | 2.3% | Jan 8, 2021 | Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised t... |
| CVE-2020-16024 | CRITICAL | 9.6 | 1.9% | Jan 8, 2021 | Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rend... |
| CVE-2020-16018 | CRITICAL | 9.6 | 1.0% | Jan 8, 2021 | Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rend... |
| CVE-2020-16017 | CRITICAL | 9.6 | 2.7% | Jan 8, 2021 | Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised t... |
| CVE-2020-16016 | CRITICAL | 9.6 | 0.9% | Jan 8, 2021 | Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromis... |
| CVE-2020-16014 | CRITICAL | 9.6 | 1.0% | Jan 8, 2021 | Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rendere... |
| CVE-2020-35131 | CRITICAL | 9.8 | 49.9% | Jan 8, 2021 | Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCrite... |
| CVE-2020-8584 | CRITICAL | 9.8 | 4.2% | Jan 8, 2021 | Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remot... |
| CVE-2020-7794 | CRITICAL | 9.8 | 1.6% | Jan 8, 2021 | This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the ... |
| CVE-2020-7784 | CRITICAL | 9.8 | 1.4% | Jan 8, 2021 | This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of pac... |
| CVE-2020-28468 | CRITICAL | 9.8 | 4.2% | Jan 8, 2021 | This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulner... |
| CVE-2020-13452 | CRITICAL | 9.8 | 2.7% | Jan 7, 2021 | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now