2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15709 | MEDIUM | 5.5 | 0.3% | Sep 5, 2020 | Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (p... |
| CVE-2020-24987 | CRITICAL | 9.8 | 3.1% | Sep 4, 2020 | Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution ... |
| CVE-2020-24986 | HIGH | 7.2 | 2.0% | Sep 4, 2020 | Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File ... |
| CVE-2020-24981 | MEDIUM | 5.3 | 1.0% | Sep 4, 2020 | An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an... |
| CVE-2020-24963 | MEDIUM | 5.4 | 1.9% | Sep 4, 2020 | An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4. |
| CVE-2020-24659 | HIGH | 7.5 | 3.7% | Sep 4, 2020 | An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if ... |
| CVE-2020-14008 | HIGH | 7.2 | 35.5% | Sep 4, 2020 | Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in... |
| CVE-2020-7299 | MEDIUM | 4.1 | 0.4% | Sep 4, 2020 | Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) p... |
| CVE-2020-4702 | MEDIUM | 5.4 | 0.6% | Sep 4, 2020 | IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to ... |
| CVE-2020-4632 | MEDIUM | 6.5 | 0.9% | Sep 4, 2020 | IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted ... |
| CVE-2020-4545 | HIGH | 7.8 | 3.0% | Sep 4, 2020 | IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loadi... |
| CVE-2020-7119 | MEDIUM | 4.9 | 0.7% | Sep 4, 2020 | A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier fir... |
| CVE-2020-7730 | CRITICAL | 9.8 | 3.1% | Sep 4, 2020 | The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param. |
| CVE-2020-25023 | CRITICAL | 9.8 | 2.6% | Sep 4, 2020 | An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds ac... |
| CVE-2020-25022 | CRITICAL | 9.8 | 2.6% | Sep 4, 2020 | An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds... |
| CVE-2020-25021 | CRITICAL | 9.8 | 2.6% | Sep 4, 2020 | An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds acc... |
| CVE-2020-23834 | HIGH | 7.8 | 0.5% | Sep 4, 2020 | Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to esca... |
| CVE-2020-12248 | HIGH | 8.8 | 1.8% | Sep 4, 2020 | In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a he... |
| CVE-2020-12247 | HIGH | 7.1 | 3.6% | Sep 4, 2020 | In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information fr... |
| CVE-2020-11493 | HIGH | 8.1 | 0.9% | Sep 4, 2020 | In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information ab... |
| CVE-2020-3547 | MEDIUM | 6.5 | 0.9% | Sep 4, 2020 | A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA)... |
| CVE-2020-3546 | MEDIUM | 5.3 | 1.1% | Sep 4, 2020 | A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA)... |
| CVE-2020-3545 | MEDIUM | 6.7 | 0.4% | Sep 4, 2020 | A vulnerability in Cisco FXOS Software could allow an authenticated, local attacker with administrative credentials to c... |
| CVE-2020-3542 | MEDIUM | 5.3 | 1.1% | Sep 4, 2020 | A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeti... |
| CVE-2020-3541 | MEDIUM | 4.4 | 0.3% | Sep 4, 2020 | A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop A... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now