2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8583 | HIGH | 7.5 | 1.1% | Nov 13, 2020 | Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could a... |
| CVE-2020-8582 | MEDIUM | 6.5 | 0.9% | Nov 13, 2020 | Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could a... |
| CVE-2020-6019 | HIGH | 7.5 | 2.8% | Nov 13, 2020 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConn... |
| CVE-2020-26222 | HIGH | 8.8 | 2.9% | Nov 13, 2020 | Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Jav... |
| CVE-2020-25557 | HIGH | 8.8 | 9.9% | Nov 13, 2020 | In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. A... |
| CVE-2020-25538 | HIGH | 8.8 | 9.9% | Nov 13, 2020 | An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and r... |
| CVE-2020-25165 | HIGH | 7.5 | 1.7% | Nov 13, 2020 | BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The ... |
| CVE-2020-25155 | HIGH | 7.5 | 0.7% | Nov 13, 2020 | The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information... |
| CVE-2020-25151 | HIGH | 7.5 | 1.1% | Nov 13, 2020 | The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack... |
| CVE-2020-21667 | HIGH | 7.2 | 1.0% | Nov 13, 2020 | In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malic... |
| CVE-2020-9129 | MEDIUM | 6.7 | 0.2% | Nov 13, 2020 | HUAWEI Mate 30 versions earlier than 10.1.0.159(C00E159R7P2) have a vulnerability of improper buffer operation. Due to i... |
| CVE-2020-9127 | MEDIUM | 6.7 | 0.4% | Nov 13, 2020 | Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high... |
| CVE-2020-6156 | HIGH | 7.8 | 1.3% | Nov 13, 2020 | A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f... |
| CVE-2020-6155 | HIGH | 7.8 | 2.6% | Nov 13, 2020 | A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 while parsing compressed value rep arrays in binary USD ... |
| CVE-2020-6150 | HIGH | 7.8 | 1.3% | Nov 13, 2020 | A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software USDC file format SPECS section decompressi... |
| CVE-2020-6149 | HIGH | 7.8 | 1.3% | Nov 13, 2020 | A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f... |
| CVE-2020-6148 | HIGH | 7.8 | 1.3% | Nov 13, 2020 | A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f... |
| CVE-2020-6147 | HIGH | 7.8 | 1.4% | Nov 13, 2020 | A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f... |
| CVE-2020-4886 | LOW | 3.3 | 0.3% | Nov 13, 2020 | IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a... |
| CVE-2020-26825 | MEDIUM | 6.1 | 0.6% | Nov 13, 2020 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use ... |
| CVE-2020-1847 | HIGH | 7.5 | 0.7% | Nov 13, 2020 | There is a denial of service vulnerability in some Huawei products. There is no protection against the attack scenario o... |
| CVE-2020-7032 | MEDIUM | 6.5 | 3.5% | Nov 13, 2020 | An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary f... |
| CVE-2020-7033 | MEDIUM | 5.4 | 0.6% | Nov 13, 2020 | A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing ... |
| CVE-2020-27193 | MEDIUM | 6.1 | 2.0% | Nov 12, 2020 | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run... |
| CVE-2020-24719 | CRITICAL | 9.8 | 23.3% | Nov 12, 2020 | Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now