2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15645 | HIGH | 8.8 | 10.7% | Aug 25, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso... |
| CVE-2020-15644 | HIGH | 8.8 | 9.3% | Aug 25, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso... |
| CVE-2020-15643 | HIGH | 8.8 | 59.3% | Aug 25, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso... |
| CVE-2020-15642 | HIGH | 8.8 | 7.2% | Aug 25, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marve... |
| CVE-2020-15641 | HIGH | 7.5 | 3.2% | Aug 25, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConve... |
| CVE-2020-15640 | HIGH | 7.5 | 3.2% | Aug 25, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConve... |
| CVE-2020-15639 | CRITICAL | 9.8 | 11.5% | Aug 25, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso... |
| CVE-2020-7824 | MEDIUM | 6.5 | 1.0% | Aug 25, 2020 | A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get admi... |
| CVE-2020-24622 | MEDIUM | 4.9 | 1.0% | Aug 25, 2020 | In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user. |
| CVE-2020-16245 | CRITICAL | 9.8 | 7.7% | Aug 25, 2020 | Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could... |
| CVE-2020-16197 | MEDIUM | 4.3 | 0.5% | Aug 25, 2020 | An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that... |
| CVE-2020-24616 | HIGH | 8.1 | 9.4% | Aug 25, 2020 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-24609 | MEDIUM | 6.1 | 9.8% | Aug 25, 2020 | TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the X... |
| CVE-2020-14042 | MEDIUM | 6.1 | 1.2% | Aug 25, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and late... |
| CVE-2020-24614 | HIGH | 8.8 | 3.1% | Aug 25, 2020 | Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitr... |
| CVE-2020-24242 | MEDIUM | 5.5 | 0.7% | Aug 25, 2020 | In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory. |
| CVE-2020-24241 | MEDIUM | 5.5 | 0.8% | Aug 25, 2020 | In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c. |
| CVE-2020-24240 | MEDIUM | 5.5 | 1.3% | Aug 25, 2020 | GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is... |
| CVE-2020-14524 | CRITICAL | 9.8 | 2.5% | Aug 25, 2020 | Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerab... |
| CVE-2020-14522 | HIGH | 7.5 | 1.5% | Aug 25, 2020 | Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerab... |
| CVE-2020-14512 | HIGH | 7.5 | 0.8% | Aug 25, 2020 | GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user... |
| CVE-2020-14510 | CRITICAL | 9.8 | 2.5% | Aug 25, 2020 | GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unpriv... |
| CVE-2020-14508 | CRITICAL | 9.8 | 2.0% | Aug 25, 2020 | GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attack... |
| CVE-2020-14500 | CRITICAL | 9.8 | 1.7% | Aug 25, 2020 | Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data. |
| CVE-2020-17386 | MEDIUM | 6.5 | 1.1% | Aug 25, 2020 | Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user,... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now