2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10049 | HIGH | 7.3 | 0.3% | Sep 9, 2020 | A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts fo... |
| CVE-2020-7068 | LOW | 3.6 | 1.7% | Sep 9, 2020 | In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar ext... |
| CVE-2020-15163 | HIGH | 8.2 | 0.6% | Sep 9, 2020 | Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously do... |
| CVE-2020-13127 | HIGH | 8.8 | 1.4% | Sep 9, 2020 | A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.04.1 allows remote authenticated attackers to... |
| CVE-2020-2044 | LOW | 3.3 | 0.7% | Sep 9, 2020 | An information exposure through log file vulnerability where an administrator's password or other sensitive information ... |
| CVE-2020-2043 | LOW | 3.3 | 0.7% | Sep 9, 2020 | An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log with... |
| CVE-2020-2042 | HIGH | 7.2 | 2.3% | Sep 9, 2020 | A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt sy... |
| CVE-2020-2041 | HIGH | 7.5 | 2.1% | Sep 9, 2020 | An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to ... |
| CVE-2020-2040 | CRITICAL | 9.8 | 3.9% | Sep 9, 2020 | A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially... |
| CVE-2020-2039 | MEDIUM | 5.3 | 46.4% | Sep 9, 2020 | An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user... |
| CVE-2020-2038 | HIGH | 7.2 | 86.1% | Sep 9, 2020 | An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to exe... |
| CVE-2020-2037 | HIGH | 7.2 | 3.6% | Sep 9, 2020 | An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to exe... |
| CVE-2020-2036 | HIGH | 8.8 | 23.9% | Sep 9, 2020 | A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker ab... |
| CVE-2020-14292 | MEDIUM | 5.7 | 1.3% | Sep 9, 2020 | In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connec... |
| CVE-2020-25213 | CRITICAL | 9.8 | 97.3% | Sep 9, 2020 | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra... |
| CVE-2020-25212 | HIGH | 7 | 0.3% | Sep 9, 2020 | A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt me... |
| CVE-2020-25211 | MEDIUM | 6 | 0.6% | Sep 9, 2020 | In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local... |
| CVE-2020-24566 | HIGH | 7.5 | 1.8% | Sep 9, 2020 | In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment o... |
| CVE-2020-11986 | CRITICAL | 9.8 | 9.9% | Sep 9, 2020 | To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This... |
| CVE-2020-24794 | MEDIUM | 6.1 | 0.9% | Sep 9, 2020 | Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75. |
| CVE-2020-24200 | — | — | — | Sep 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-24199 | CRITICAL | 9.8 | 3.7% | Sep 9, 2020 | Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows a... |
| CVE-2020-24198 | MEDIUM | 6.1 | 0.8% | Sep 9, 2020 | A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers t... |
| CVE-2020-24195 | CRITICAL | 9.1 | 2.9% | Sep 9, 2020 | An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated ad... |
| CVE-2020-1749 | HIGH | 7.5 | 1.2% | Sep 9, 2020 | A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tu... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now