2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7752 | HIGH | 8.8 | 5.7% | Oct 26, 2020 | This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker... |
| CVE-2020-27187 | HIGH | 7.8 | 0.4% | Oct 26, 2020 | An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic... |
| CVE-2020-7197 | CRITICAL | 9.8 | 2.2% | Oct 26, 2020 | SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off nod... |
| CVE-2020-7196 | MEDIUM | 6.5 | 0.9% | Oct 26, 2020 | The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of han... |
| CVE-2020-7127 | CRITICAL | 9.8 | 1.8% | Oct 26, 2020 | A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Pri... |
| CVE-2020-7126 | MEDIUM | 5.8 | 0.8% | Oct 26, 2020 | A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to ... |
| CVE-2020-7125 | HIGH | 8.8 | 1.4% | Oct 26, 2020 | A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
| CVE-2020-7124 | CRITICAL | 9.8 | 1.4% | Oct 26, 2020 | A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
| CVE-2020-6876 | MEDIUM | 5.4 | 0.6% | Oct 26, 2020 | A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of cl... |
| CVE-2020-24632 | HIGH | 7.2 | 2.6% | Oct 26, 2020 | A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.... |
| CVE-2020-24631 | HIGH | 7.2 | 2.6% | Oct 26, 2020 | A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3... |
| CVE-2020-18766 | CRITICAL | 9.6 | 1.1% | Oct 26, 2020 | A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands. |
| CVE-2020-15897 | HIGH | 7.5 | 1.3% | Oct 26, 2020 | Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attack... |
| CVE-2020-13100 | HIGH | 7.5 | 1.3% | Oct 26, 2020 | Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x bef... |
| CVE-2020-25470 | MEDIUM | 6.1 | 1.3% | Oct 26, 2020 | AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added sit... |
| CVE-2020-7751 | HIGH | 7.2 | 1.5% | Oct 26, 2020 | pathval before version 1.1.1 is vulnerable to prototype pollution. |
| CVE-2020-27678 | CRITICAL | 9.8 | 1.4% | Oct 26, 2020 | An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and Sm... |
| CVE-2020-27388 | MEDIUM | 5.4 | 0.8% | Oct 23, 2020 | Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An au... |
| CVE-2020-24848 | HIGH | 7.8 | 0.4% | Oct 23, 2020 | FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform ... |
| CVE-2020-24847 | MEDIUM | 4.3 | 0.4% | Oct 23, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protect... |
| CVE-2020-5990 | HIGH | 7.8 | 0.4% | Oct 23, 2020 | NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which m... |
| CVE-2020-5978 | HIGH | 7.8 | 0.3% | Oct 23, 2020 | NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in its services in which a folder i... |
| CVE-2020-5977 | HIGH | 7.8 | 0.4% | Oct 23, 2020 | NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Ser... |
| CVE-2020-25483 | CRITICAL | 9.8 | 8.6% | Oct 23, 2020 | An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an atta... |
| CVE-2020-25466 | CRITICAL | 9.8 | 3.0% | Oct 23, 2020 | A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now