2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26105 | CRITICAL | 9.8 | 1.4% | Sep 25, 2020 | In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554). |
| CVE-2020-26104 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552). |
| CVE-2020-26103 | HIGH | 7.5 | 1.3% | Sep 25, 2020 | In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551). |
| CVE-2020-26102 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550). |
| CVE-2020-26101 | CRITICAL | 9.8 | 1.4% | Sep 25, 2020 | In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549). |
| CVE-2020-26100 | CRITICAL | 9.8 | 1.6% | Sep 25, 2020 | chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497). |
| CVE-2020-26099 | HIGH | 7.5 | 1.2% | Sep 25, 2020 | cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491). |
| CVE-2020-26098 | CRITICAL | 9.8 | 3.0% | Sep 25, 2020 | cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). |
| CVE-2020-25625 | MEDIUM | 5.3 | 0.4% | Sep 25, 2020 | hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop. |
| CVE-2020-25085 | MEDIUM | 5 | 0.6% | Sep 25, 2020 | QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write... |
| CVE-2020-25084 | LOW | 3.2 | 0.3% | Sep 25, 2020 | QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked. |
| CVE-2020-25749 | CRITICAL | 9.8 | 3.1% | Sep 25, 2020 | The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow a... |
| CVE-2020-25748 | HIGH | 8.1 | 0.8% | Sep 25, 2020 | A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, ... |
| CVE-2020-25747 | CRITICAL | 9.4 | 1.8% | Sep 25, 2020 | The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote at... |
| CVE-2020-25726 | — | — | — | Sep 25, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-25223 | CRITICAL | 9.8 | 96.7% | Sep 25, 2020 | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 ... |
| CVE-2020-25203 | MEDIUM | 5.5 | 0.5% | Sep 25, 2020 | The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By cal... |
| CVE-2020-24718 | HIGH | 8.2 | 0.6% | Sep 25, 2020 | bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020... |
| CVE-2020-24692 | HIGH | 7.1 | 0.4% | Sep 25, 2020 | The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts... |
| CVE-2020-24621 | HIGH | 8.8 | 3.1% | Sep 25, 2020 | A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11... |
| CVE-2020-24615 | MEDIUM | 5.3 | 1.0% | Sep 25, 2020 | Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP. |
| CVE-2020-24595 | MEDIUM | 5.3 | 0.9% | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensit... |
| CVE-2020-24594 | CRITICAL | 9.6 | 1.7% | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due ... |
| CVE-2020-24593 | HIGH | 7.2 | 1.1% | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and acces... |
| CVE-2020-24592 | MEDIUM | 5.3 | 0.9% | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system inf... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now