2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26276 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsi... |
| CVE-2020-35489 | CRITICAL | 10 | 89.3% | Dec 17, 2020 | The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote cod... |
| CVE-2020-22083 | CRITICAL | 9.8 | 6.1% | Dec 17, 2020 | jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode()... |
| CVE-2020-25011 | CRITICAL | 9.8 | 1.6% | Dec 17, 2020 | A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Se... |
| CVE-2020-25010 | CRITICAL | 9.8 | 2.4% | Dec 17, 2020 | An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers S... |
| CVE-2020-25094 | CRITICAL | 9.8 | 3.1% | Dec 17, 2020 | LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program nam... |
| CVE-2020-35197 | CRITICAL | 9.8 | 2.1% | Dec 17, 2020 | The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. Sy... |
| CVE-2020-35196 | CRITICAL | 9.8 | 2.1% | Dec 17, 2020 | The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password fo... |
| CVE-2020-35195 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. Syst... |
| CVE-2020-35192 | CRITICAL | 9.8 | 2.9% | Dec 17, 2020 | The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker c... |
| CVE-2020-35191 | CRITICAL | 9.8 | 4.6% | Dec 17, 2020 | The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. S... |
| CVE-2020-35190 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root u... |
| CVE-2020-35186 | CRITICAL | 9.8 | 2.9% | Dec 17, 2020 | The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the admin... |
| CVE-2020-35184 | CRITICAL | 9.8 | 3.0% | Dec 17, 2020 | The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer doc... |
| CVE-2020-35189 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System u... |
| CVE-2020-35187 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. Syst... |
| CVE-2020-35185 | CRITICAL | 9.8 | 2.8% | Dec 17, 2020 | The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System... |
| CVE-2020-28929 | CRITICAL | 9.8 | 1.2% | Dec 16, 2020 | Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated at... |
| CVE-2020-7781 | CRITICAL | 9.8 | 2.0% | Dec 16, 2020 | This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The foll... |
| CVE-2020-35476 | CRITICAL | 9.8 | 85.3% | Dec 16, 2020 | A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. Th... |
| CVE-2020-35469 | CRITICAL | 9.8 | 2.1% | Dec 16, 2020 | The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed u... |
| CVE-2020-35468 | CRITICAL | 9.8 | 2.1% | Dec 16, 2020 | The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected vers... |
| CVE-2020-35193 | CRITICAL | 9.8 | 2.1% | Dec 16, 2020 | The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System us... |
| CVE-2020-35467 | CRITICAL | 9.8 | 2.2% | Dec 15, 2020 | The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affe... |
| CVE-2020-35466 | CRITICAL | 9.8 | 2.1% | Dec 15, 2020 | The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affect... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now