2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24056 | HIGH | 7.5 | 1.2% | Aug 21, 2020 | A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31,... |
| CVE-2020-24055 | CRITICAL | 9.8 | 1.6% | Aug 21, 2020 | Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service im... |
| CVE-2020-24054 | CRITICAL | 9.8 | 2.6% | Aug 21, 2020 | The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that... |
| CVE-2020-24053 | HIGH | 7.5 | 1.2% | Aug 21, 2020 | Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidential... |
| CVE-2020-24052 | CRITICAL | 9.1 | 1.9% | Aug 21, 2020 | Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unaut... |
| CVE-2020-24051 | CRITICAL | 9.8 | 2.2% | Aug 21, 2020 | The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol,... |
| CVE-2020-20634 | MEDIUM | 6.5 | 1.0% | Aug 21, 2020 | Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exp... |
| CVE-2020-10290 | MEDIUM | 6.8 | 0.4% | Aug 21, 2020 | Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restr... |
| CVE-2020-9246 | MEDIUM | 6.5 | 0.6% | Aug 21, 2020 | FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and informatio... |
| CVE-2020-9104 | MEDIUM | 4.3 | 0.3% | Aug 21, 2020 | HUAWEI P30 smartphones with Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1.0.123(C432E22R2P5),... |
| CVE-2020-9096 | MEDIUM | 5.5 | 0.2% | Aug 21, 2020 | HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. S... |
| CVE-2020-9095 | MEDIUM | 5.5 | 0.2% | Aug 21, 2020 | HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow vulnerability. Some... |
| CVE-2020-24585 | MEDIUM | 5.3 | 0.9% | Aug 21, 2020 | An issue was discovered in the DTLS handshake implementation in wolfSSL before 4.5.0. Clear DTLS application_data messag... |
| CVE-2020-15309 | HIGH | 7 | 0.3% | Aug 21, 2020 | An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a ca... |
| CVE-2020-12457 | HIGH | 7.5 | 1.5% | Aug 21, 2020 | An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for... |
| CVE-2020-5774 | HIGH | 7.1 | 0.3% | Aug 21, 2020 | Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios... |
| CVE-2020-3976 | MEDIUM | 5.3 | 2.1% | Aug 21, 2020 | VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication serv... |
| CVE-2020-16241 | LOW | 2.1 | 0.2% | Aug 21, 2020 | Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unaut... |
| CVE-2020-16239 | MEDIUM | 4.9 | 0.9% | Aug 21, 2020 | When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficie... |
| CVE-2020-16237 | LOW | 2.1 | 0.3% | Aug 21, 2020 | Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that... |
| CVE-2020-14518 | MEDIUM | 5.3 | 1.3% | Aug 21, 2020 | Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker. |
| CVE-2020-7710 | CRITICAL | 9.8 | 1.4% | Aug 21, 2020 | This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host m... |
| CVE-2020-7310 | MEDIUM | 6.9 | 0.3% | Aug 21, 2020 | Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 all... |
| CVE-2020-15070 | HIGH | 8.8 | 1.2% | Aug 21, 2020 | Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres... |
| CVE-2020-14215 | HIGH | 7.5 | 0.9% | Aug 21, 2020 | Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrato... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now