2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14194 | MEDIUM | 5.4 | 0.7% | Aug 21, 2020 | Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link. |
| CVE-2020-12759 | MEDIUM | 6.1 | 0.7% | Aug 21, 2020 | Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook. |
| CVE-2020-24574 | HIGH | 7.8 | 0.6% | Aug 21, 2020 | The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local pri... |
| CVE-2020-24571 | HIGH | 7.5 | 18.0% | Aug 21, 2020 | NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal. |
| CVE-2020-24567 | HIGH | 7.8 | 0.6% | Aug 21, 2020 | voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file... |
| CVE-2020-12619 | MEDIUM | 5.9 | 0.4% | Aug 20, 2020 | MailMate before 1.11 automatically imported S/MIME certificates and thereby silently replaced existing ones. This allowe... |
| CVE-2020-12618 | MEDIUM | 4.8 | 0.3% | Aug 20, 2020 | eM Client before 7.2.33412.0 automatically imported S/MIME certificates and thereby silently replaced existing ones. Thi... |
| CVE-2020-24359 | HIGH | 7.5 | 1.0% | Aug 20, 2020 | HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet i... |
| CVE-2020-4687 | MEDIUM | 4.3 | 1.0% | Aug 20, 2020 | IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they... |
| CVE-2020-4548 | LOW | 2.7 | 0.7% | Aug 20, 2020 | IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass... |
| CVE-2020-16282 | HIGH | 8.8 | 0.4% | Aug 20, 2020 | In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged... |
| CVE-2020-16281 | HIGH | 7.8 | 0.3% | Aug 20, 2020 | The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restri... |
| CVE-2020-16280 | MEDIUM | 5.5 | 0.3% | Aug 20, 2020 | Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several ex... |
| CVE-2020-16279 | CRITICAL | 9.8 | 2.3% | Aug 20, 2020 | The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplie... |
| CVE-2020-23935 | CRITICAL | 9.8 | 15.9% | Aug 20, 2020 | Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (... |
| CVE-2020-23936 | CRITICAL | 9.8 | 1.4% | Aug 20, 2020 | PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Passwo... |
| CVE-2020-14357 | — | — | — | Aug 20, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-10283 | CRITICAL | 9.8 | 1.5% | Aug 20, 2020 | The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to... |
| CVE-2020-10289 | HIGH | 8.8 | 1.9% | Aug 20, 2020 | Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YA... |
| CVE-2020-8870 | HIGH | 7.8 | 5.0% | Aug 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8869 | HIGH | 7.8 | 5.0% | Aug 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-17456 | CRITICAL | 9.8 | 70.9% | Aug 20, 2020 | SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa... |
| CVE-2020-15862 | HIGH | 7.8 | 0.4% | Aug 20, 2020 | Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability ... |
| CVE-2020-15861 | HIGH | 7.8 | 0.5% | Aug 20, 2020 | Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. |
| CVE-2020-15638 | HIGH | 7.8 | 6.1% | Aug 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.2... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now