2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26822 | CRITICAL | 10 | 1.3% | Nov 10, 2020 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o... |
| CVE-2020-26821 | CRITICAL | 10 | 1.3% | Nov 10, 2020 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o... |
| CVE-2020-25074 | CRITICAL | 9.8 | 6.1% | Nov 10, 2020 | The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request... |
| CVE-2020-7766 | CRITICAL | 9.8 | 1.9% | Nov 10, 2020 | This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr... |
| CVE-2020-13927 | CRITICAL | 9.8 | 99.7% | Nov 10, 2020 | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th... |
| CVE-2020-24384 | CRITICAL | 9.8 | 3.4% | Nov 10, 2020 | A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution ... |
| CVE-2020-0452 | CRITICAL | 9.8 | 3.2% | Nov 10, 2020 | In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could ... |
| CVE-2020-0447 | CRITICAL | 9.8 | 0.6% | Nov 10, 2020 | There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A... |
| CVE-2020-0446 | CRITICAL | 9.8 | 0.5% | Nov 10, 2020 | There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A... |
| CVE-2020-0445 | CRITICAL | 9.8 | 0.5% | Nov 10, 2020 | There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A... |
| CVE-2020-28371 | CRITICAL | 9.8 | 1.7% | Nov 9, 2020 | An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. The FileOutputStream.write() method in FileOutputStr... |
| CVE-2020-26168 | CRITICAL | 9.8 | 1.6% | Nov 9, 2020 | The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x ... |
| CVE-2020-14189 | CRITICAL | 9.8 | 2.3% | Nov 9, 2020 | The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to ex... |
| CVE-2020-14188 | CRITICAL | 9.8 | 2.8% | Nov 9, 2020 | The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to... |
| CVE-2020-26542 | CRITICAL | 9.8 | 1.5% | Nov 9, 2020 | An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDA... |
| CVE-2020-23138 | CRITICAL | 9.8 | 1.3% | Nov 9, 2020 | An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can up... |
| CVE-2020-15297 | CRITICAL | 9.1 | 0.8% | Nov 9, 2020 | Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tool... |
| CVE-2020-24407 | CRITICAL | 9.1 | 5.5% | Nov 9, 2020 | Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result i... |
| CVE-2020-28347 | CRITICAL | 9.8 | 73.8% | Nov 8, 2020 | tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl... |
| CVE-2020-28340 | CRITICAL | 9.8 | 0.4% | Nov 8, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypa... |
| CVE-2020-3284 | CRITICAL | 9.8 | 2.8% | Nov 6, 2020 | A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could a... |
| CVE-2020-26214 | CRITICAL | 9.8 | 65.9% | Nov 6, 2020 | In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when A... |
| CVE-2020-25172 | CRITICAL | 9.8 | 2.0% | Nov 6, 2020 | A relative path traversal attack in the B. Braun OnlineSuite Version AP 3.0 and earlier allows unauthenticated attackers... |
| CVE-2020-26892 | CRITICAL | 9.8 | 2.1% | Nov 6, 2020 | The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are han... |
| CVE-2020-25592 | CRITICAL | 9.8 | 57.5% | Nov 6, 2020 | In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authent... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now