2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28351 | MEDIUM | 6.1 | 16.0% | Nov 9, 2020 | The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r... |
| CVE-2020-28349 | MEDIUM | 6.5 | 2.2% | Nov 9, 2020 | An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplin... |
| CVE-2020-24407 | CRITICAL | 9.1 | 5.5% | Nov 9, 2020 | Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result i... |
| CVE-2020-24406 | LOW | 3.7 | 2.1% | Nov 9, 2020 | When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulner... |
| CVE-2020-24405 | MEDIUM | 4.3 | 1.5% | Nov 9, 2020 | Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inve... |
| CVE-2020-24404 | LOW | 2.7 | 1.6% | Nov 9, 2020 | Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integr... |
| CVE-2020-24403 | LOW | 2.7 | 1.6% | Nov 9, 2020 | Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the I... |
| CVE-2020-24402 | MEDIUM | 4.9 | 1.7% | Nov 9, 2020 | Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integratio... |
| CVE-2020-24401 | MEDIUM | 6.5 | 2.3% | Nov 9, 2020 | Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can st... |
| CVE-2020-24400 | HIGH | 7.1 | 2.3% | Nov 9, 2020 | Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensiti... |
| CVE-2020-28347 | CRITICAL | 9.8 | 73.8% | Nov 8, 2020 | tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl... |
| CVE-2020-7764 | HIGH | 7.5 | 1.7% | Nov 8, 2020 | This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by... |
| CVE-2020-28345 | HIGH | 7.5 | 0.4% | Nov 8, 2020 | An issue was discovered on LG mobile devices with Android OS 10 software. The Wi-Fi subsystem may crash because of the l... |
| CVE-2020-28344 | HIGH | 7.5 | 0.4% | Nov 8, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. System services may crash b... |
| CVE-2020-28343 | HIGH | 7.8 | 0.2% | Nov 8, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software... |
| CVE-2020-28342 | HIGH | 7.8 | 0.3% | Nov 8, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software. The S Secure applica... |
| CVE-2020-28341 | HIGH | 7.8 | 0.2% | Nov 8, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Elemen... |
| CVE-2020-28340 | CRITICAL | 9.8 | 0.4% | Nov 8, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypa... |
| CVE-2020-28339 | HIGH | 8.8 | 1.9% | Nov 7, 2020 | The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usc... |
| CVE-2020-16122 | HIGH | 7.8 | 0.3% | Nov 7, 2020 | PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository tru... |
| CVE-2020-16121 | LOW | 3.3 | 0.5% | Nov 7, 2020 | PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mim... |
| CVE-2020-28168 | MEDIUM | 5.9 | 2.3% | Nov 6, 2020 | Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass... |
| CVE-2020-15259 | HIGH | 8.8 | 0.9% | Nov 6, 2020 | ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result ... |
| CVE-2020-3604 | HIGH | 7.8 | 2.4% | Nov 6, 2020 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could al... |
| CVE-2020-3603 | HIGH | 7.8 | 2.5% | Nov 6, 2020 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could al... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now