2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13638 | CRITICAL | 9.8 | 76.8% | Nov 13, 2020 | lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account cr... |
| CVE-2020-12338 | CRITICAL | 9.8 | 1.6% | Nov 13, 2020 | Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user t... |
| CVE-2020-24719 | CRITICAL | 9.8 | 23.3% | Nov 12, 2020 | Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by... |
| CVE-2020-13877 | CRITICAL | 9.8 | 2.1% | Nov 12, 2020 | SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and... |
| CVE-2020-13774 | CRITICAL | 9.9 | 4.7% | Nov 12, 2020 | An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an aut... |
| CVE-2020-12315 | CRITICAL | 9.8 | 1.7% | Nov 12, 2020 | Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalati... |
| CVE-2020-8752 | CRITICAL | 9.8 | 1.6% | Nov 12, 2020 | Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.7... |
| CVE-2020-8747 | CRITICAL | 9.1 | 1.7% | Nov 12, 2020 | Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may al... |
| CVE-2020-7472 | CRITICAL | 9.8 | 3.1% | Nov 12, 2020 | An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8... |
| CVE-2020-28271 | CRITICAL | 9.8 | 3.3% | Nov 12, 2020 | Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service... |
| CVE-2020-28270 | CRITICAL | 9.8 | 3.7% | Nov 12, 2020 | Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a ... |
| CVE-2020-28269 | CRITICAL | 9.8 | 4.0% | Nov 12, 2020 | Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service a... |
| CVE-2020-27481 | CRITICAL | 9.8 | 10.6% | Nov 12, 2020 | An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_no... |
| CVE-2020-7770 | CRITICAL | 9.8 | 1.9% | Nov 12, 2020 | This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, ... |
| CVE-2020-3639 | CRITICAL | 9.8 | 0.9% | Nov 12, 2020 | u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cyc... |
| CVE-2020-11196 | CRITICAL | 9.8 | 0.9% | Nov 12, 2020 | u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Sn... |
| CVE-2020-11193 | CRITICAL | 9.8 | 0.9% | Nov 12, 2020 | u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snap... |
| CVE-2020-11184 | CRITICAL | 9.8 | 0.9% | Nov 12, 2020 | u'Possible buffer overflow will occur in video while parsing mp4 clip with crafted esds atom size.' in Snapdragon Auto, ... |
| CVE-2020-11168 | CRITICAL | 9.8 | 0.9% | Nov 12, 2020 | u'Null-pointer dereference can occur while accessing data buffer beyond its size that leads to access the buffer beyond ... |
| CVE-2020-7769 | CRITICAL | 9.8 | 2.3% | Nov 12, 2020 | This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary comm... |
| CVE-2020-5426 | CRITICAL | 9.8 | 0.7% | Nov 11, 2020 | Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a ... |
| CVE-2020-7768 | CRITICAL | 9.8 | 3.6% | Nov 11, 2020 | The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPac... |
| CVE-2020-17051 | CRITICAL | 9.8 | 9.9% | Nov 11, 2020 | Windows Network File System Remote Code Execution Vulnerability |
| CVE-2020-26824 | CRITICAL | 10 | 1.3% | Nov 10, 2020 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o... |
| CVE-2020-26823 | CRITICAL | 10 | 1.3% | Nov 10, 2020 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now