2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35464 | CRITICAL | 9.8 | 2.1% | Dec 15, 2020 | Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using ... |
| CVE-2020-35463 | CRITICAL | 9.8 | 2.1% | Dec 15, 2020 | Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed usin... |
| CVE-2020-35462 | CRITICAL | 9.8 | 2.1% | Dec 15, 2020 | Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using aff... |
| CVE-2020-29663 | CRITICAL | 9.1 | 1.6% | Dec 15, 2020 | Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically b... |
| CVE-2020-27068 | CRITICAL | 9.8 | 0.8% | Dec 15, 2020 | Product: AndroidVersions: Android kernelAndroid ID: A-127973231References: Upstream kernel |
| CVE-2020-4747 | CRITICAL | 9.8 | 2.0% | Dec 15, 2020 | IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated C... |
| CVE-2020-28442 | CRITICAL | 9.8 | 2.0% | Dec 15, 2020 | All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function. |
| CVE-2020-0456 | CRITICAL | 9.8 | 0.7% | Dec 14, 2020 | There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A... |
| CVE-2020-0457 | CRITICAL | 9.8 | 0.7% | Dec 14, 2020 | There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A... |
| CVE-2020-0455 | CRITICAL | 9.8 | 0.7% | Dec 14, 2020 | There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A... |
| CVE-2020-25228 | CRITICAL | 9.8 | 1.4% | Dec 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on ... |
| CVE-2020-20189 | CRITICAL | 9.8 | 1.1% | Dec 14, 2020 | SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php. |
| CVE-2020-8257 | CRITICAL | 9.8 | 1.6% | Dec 14, 2020 | Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-... |
| CVE-2020-25187 | CRITICAL | 9.8 | 3.9% | Dec 14, 2020 | Medtronic MyCareLink Smart 25000 is vulnerable when an authenticated attacker runs a debug command, which can be sent... |
| CVE-2020-20184 | CRITICAL | 9.8 | 2.7% | Dec 14, 2020 | GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting... |
| CVE-2020-20136 | CRITICAL | 9.8 | 1.5% | Dec 14, 2020 | QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to inse... |
| CVE-2020-35338 | CRITICAL | 9.8 | 11.7% | Dec 14, 2020 | The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier... |
| CVE-2020-25179 | CRITICAL | 9.8 | 1.4% | Dec 14, 2020 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net... |
| CVE-2020-25175 | CRITICAL | 9.8 | 1.1% | Dec 14, 2020 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net... |
| CVE-2020-35378 | CRITICAL | 9.8 | 2.0% | Dec 14, 2020 | SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands ... |
| CVE-2020-14268 | CRITICAL | 9.8 | 2.2% | Dec 14, 2020 | A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by a... |
| CVE-2020-14244 | CRITICAL | 9.8 | 3.0% | Dec 14, 2020 | A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by ... |
| CVE-2020-29227 | CRITICAL | 9.8 | 16.8% | Dec 14, 2020 | An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack... |
| CVE-2020-5639 | CRITICAL | 9.8 | 5.0% | Dec 14, 2020 | Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitra... |
| CVE-2020-29563 | CRITICAL | 9.8 | 2.9% | Dec 12, 2020 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vuln... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now