2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7788 | CRITICAL | 9.8 | 3.6% | Dec 11, 2020 | This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it ... |
| CVE-2020-13556 | CRITICAL | 9.8 | 4.5% | Dec 11, 2020 | An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and de... |
| CVE-2020-24634 | CRITICAL | 9.8 | 2.1% | Dec 11, 2020 | An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Ar... |
| CVE-2020-24633 | CRITICAL | 9.8 | 4.9% | Dec 11, 2020 | There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending e... |
| CVE-2020-17530 | CRITICAL | 9.8 | 95.9% | Dec 11, 2020 | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected ... |
| CVE-2020-7540 | CRITICAL | 9.8 | 2.1% | Dec 11, 2020 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy O... |
| CVE-2020-28215 | CRITICAL | 9.8 | 2.2% | Dec 11, 2020 | A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide ... |
| CVE-2020-29311 | CRITICAL | 9.8 | 6.3% | Dec 10, 2020 | Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside th... |
| CVE-2020-26201 | CRITICAL | 9.8 | 2.4% | Dec 10, 2020 | Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. Th... |
| CVE-2020-19527 | CRITICAL | 9.8 | 1.5% | Dec 10, 2020 | iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/inst... |
| CVE-2020-19142 | CRITICAL | 9.8 | 1.5% | Dec 10, 2020 | iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install... |
| CVE-2020-16608 | CRITICAL | 9.6 | 4.3% | Dec 10, 2020 | Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in web... |
| CVE-2020-29667 | CRITICAL | 9.8 | 3.2% | Dec 10, 2020 | In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSI... |
| CVE-2020-24445 | CRITICAL | 9 | 2.5% | Dec 10, 2020 | AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS... |
| CVE-2020-17142 | CRITICAL | 9.1 | 3.5% | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability |
| CVE-2020-17132 | CRITICAL | 9.1 | 89.8% | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability |
| CVE-2020-29659 | CRITICAL | 9.8 | 5.1% | Dec 9, 2020 | A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execut... |
| CVE-2020-26838 | CRITICAL | 9.1 | 2.2% | Dec 9, 2020 | SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions... |
| CVE-2020-26837 | CRITICAL | 9.1 | 1.9% | Dec 9, 2020 | SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious... |
| CVE-2020-26831 | CRITICAL | 9.6 | 1.1% | Dec 9, 2020 | SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML ... |
| CVE-2020-26829 | CRITICAL | 10 | 4.7% | Dec 9, 2020 | SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary conne... |
| CVE-2020-17529 | CRITICAL | 9.8 | 2.9% | Dec 9, 2020 | Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.... |
| CVE-2020-17528 | CRITICAL | 9.1 | 3.1% | Dec 9, 2020 | Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.... |
| CVE-2020-29657 | CRITICAL | 9.1 | 1.2% | Dec 9, 2020 | In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file. |
| CVE-2020-28274 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now