2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15929 | CRITICAL | 9.8 | 4.5% | Nov 24, 2020 | In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow ... |
| CVE-2020-28991 | CRITICAL | 9.8 | 1.7% | Nov 24, 2020 | Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also... |
| CVE-2020-4006 | CRITICAL | 9.1 | 23.8% | Nov 23, 2020 | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command i... |
| CVE-2020-28984 | CRITICAL | 9.8 | 2.2% | Nov 23, 2020 | prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, displ... |
| CVE-2020-28360 | CRITICAL | 9.8 | 2.9% | Nov 23, 2020 | Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in ind... |
| CVE-2020-28864 | CRITICAL | 9.8 | 2.8% | Nov 23, 2020 | Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspe... |
| CVE-2020-6939 | CRITICAL | 9.8 | 1.8% | Nov 23, 2020 | Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users... |
| CVE-2020-4854 | CRITICAL | 9.8 | 2.4% | Nov 23, 2020 | IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key... |
| CVE-2020-25189 | CRITICAL | 9.8 | 2.5% | Nov 21, 2020 | The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to... |
| CVE-2020-28877 | CRITICAL | 9.8 | 1.2% | Nov 20, 2020 | Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, i... |
| CVE-2020-25839 | CRITICAL | 9.8 | 1.2% | Nov 20, 2020 | NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability i... |
| CVE-2020-7561 | CRITICAL | 9.8 | 3.0% | Nov 19, 2020 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and olde... |
| CVE-2020-28212 | CRITICAL | 9.8 | 2.6% | Nov 19, 2020 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxur... |
| CVE-2020-28951 | CRITICAL | 9.8 | 1.7% | Nov 19, 2020 | libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package nam... |
| CVE-2020-11831 | CRITICAL | 9.8 | 1.4% | Nov 19, 2020 | OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovo... |
| CVE-2020-11830 | CRITICAL | 9.8 | 1.4% | Nov 19, 2020 | QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.... |
| CVE-2020-11829 | CRITICAL | 9.8 | 1.1% | Nov 19, 2020 | Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.... |
| CVE-2020-3586 | CRITICAL | 9.8 | 2.5% | Nov 18, 2020 | A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remo... |
| CVE-2020-3531 | CRITICAL | 9.8 | 2.2% | Nov 18, 2020 | A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacke... |
| CVE-2020-3470 | CRITICAL | 9.8 | 4.6% | Nov 18, 2020 | Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthentic... |
| CVE-2020-3419 | CRITICAL | 9.1 | 1.7% | Nov 18, 2020 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker ... |
| CVE-2020-28578 | CRITICAL | 9.8 | 72.3% | Nov 18, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote a... |
| CVE-2020-26097 | CRITICAL | 9.8 | 1.8% | Nov 18, 2020 | The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root ac... |
| CVE-2020-6016 | CRITICAL | 9.8 | 5.8% | Nov 18, 2020 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in ... |
| CVE-2020-28183 | CRITICAL | 9.8 | 2.5% | Nov 17, 2020 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to proce... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now