2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8272 | HIGH | 7.5 | 1.5% | Nov 16, 2020 | Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1... |
| CVE-2020-8271 | CRITICAL | 9.8 | 11.1% | Nov 16, 2020 | Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 1... |
| CVE-2020-8270 | HIGH | 8.8 | 3.3% | Nov 16, 2020 | An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD version... |
| CVE-2020-8269 | HIGH | 8.8 | 2.6% | Nov 16, 2020 | An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, ... |
| CVE-2020-8259 | HIGH | 8.1 | 0.7% | Nov 16, 2020 | Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the... |
| CVE-2020-8152 | MEDIUM | 4.4 | 0.3% | Nov 16, 2020 | Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the... |
| CVE-2020-5666 | HIGH | 7.5 | 8.4% | Nov 16, 2020 | Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '... |
| CVE-2020-2492 | HIGH | 7.2 | 1.7% | Nov 16, 2020 | If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue... |
| CVE-2020-2490 | HIGH | 7.2 | 2.2% | Nov 16, 2020 | If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue... |
| CVE-2020-25695 | HIGH | 8.8 | 46.4% | Nov 16, 2020 | A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9... |
| CVE-2020-25694 | HIGH | 8.1 | 1.6% | Nov 16, 2020 | A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9... |
| CVE-2020-28268 | HIGH | 7.5 | 3.4% | Nov 15, 2020 | Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial o... |
| CVE-2020-7772 | CRITICAL | 9.8 | 2.7% | Nov 15, 2020 | This affects the package doc-path before 2.1.2. |
| CVE-2020-28638 | CRITICAL | 9.8 | 0.7% | Nov 13, 2020 | ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing a... |
| CVE-2020-15481 | HIGH | 7.8 | 0.6% | Nov 13, 2020 | An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 B... |
| CVE-2020-6157 | MEDIUM | 4.3 | 0.7% | Nov 13, 2020 | Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a mal... |
| CVE-2020-5796 | HIGH | 7.8 | 1.9% | Nov 13, 2020 | Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the... |
| CVE-2020-27217 | HIGH | 7.5 | 1.3% | Nov 13, 2020 | In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received fro... |
| CVE-2020-13638 | CRITICAL | 9.8 | 76.8% | Nov 13, 2020 | lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account cr... |
| CVE-2020-12338 | CRITICAL | 9.8 | 1.6% | Nov 13, 2020 | Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user t... |
| CVE-2020-12313 | HIGH | 8.8 | 0.9% | Nov 13, 2020 | Insufficient control flow management in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an u... |
| CVE-2020-0599 | MEDIUM | 6.7 | 0.3% | Nov 13, 2020 | Improper access control in the PMC for some Intel(R) Processors may allow a privileged user to potentially enable escala... |
| CVE-2020-7962 | MEDIUM | 5.3 | 0.9% | Nov 13, 2020 | An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It i... |
| CVE-2020-26230 | MEDIUM | 5.3 | 1.6% | Nov 13, 2020 | Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identific... |
| CVE-2020-26223 | MEDIUM | 6.5 | 1.1% | Nov 13, 2020 | Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now