2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1889 | CRITICAL | 10 | 4.8% | Sep 3, 2020 | A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in... |
| CVE-2020-1886 | HIGH | 8.8 | 1.2% | Sep 3, 2020 | A buffer overflow in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could hav... |
| CVE-2020-9235 | MEDIUM | 5.5 | 0.2% | Sep 3, 2020 | Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2)... |
| CVE-2020-9083 | LOW | 2.4 | 0.2% | Sep 3, 2020 | HUAWEI Mate 20 smart phones with Versions earlier than 10.1.0.163(C00E160R3P8) have a denial of service (DoS) vulnerabil... |
| CVE-2020-9199 | MEDIUM | 6.8 | 0.8% | Sep 3, 2020 | B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with ... |
| CVE-2020-25125 | HIGH | 7.8 | 1.3% | Sep 3, 2020 | GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other imp... |
| CVE-2020-25124 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI. |
| CVE-2020-25123 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager. |
| CVE-2020-25122 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager. |
| CVE-2020-25121 | MEDIUM | 4.8 | 0.7% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options. |
| CVE-2020-25120 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI. |
| CVE-2020-25119 | MEDIUM | 4.8 | 0.7% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual. |
| CVE-2020-25118 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager. |
| CVE-2020-25117 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager. |
| CVE-2020-25116 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager. |
| CVE-2020-25115 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager. |
| CVE-2020-24193 | CRITICAL | 9.8 | 2.8% | Sep 3, 2020 | A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execu... |
| CVE-2020-14373 | MEDIUM | 5.5 | 0.5% | Sep 3, 2020 | A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a s... |
| CVE-2020-11579 | HIGH | 7.5 | 26.5% | Sep 3, 2020 | An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation ... |
| CVE-2020-10720 | MEDIUM | 5.5 | 0.3% | Sep 3, 2020 | A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with l... |
| CVE-2020-25102 | MEDIUM | 6.1 | 0.9% | Sep 3, 2020 | silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-S... |
| CVE-2020-24876 | CRITICAL | 9.8 | 1.7% | Sep 3, 2020 | Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which m... |
| CVE-2020-24162 | HIGH | 7.8 | 0.4% | Sep 3, 2020 | The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attack... |
| CVE-2020-24161 | HIGH | 7.8 | 0.4% | Sep 3, 2020 | Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerabi... |
| CVE-2020-24160 | HIGH | 7.8 | 0.5% | Sep 3, 2020 | Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now