2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16846 | CRITICAL | 9.8 | 99.6% | Nov 6, 2020 | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien... |
| CVE-2020-28250 | CRITICAL | 9.8 | 2.9% | Nov 6, 2020 | Cellinx NVT Web Server 5.0.0.014b.test 2019-09-05 allows a remote user to run commands as root via SetFileContent.cgi be... |
| CVE-2020-5648 | CRITICAL | 9.8 | 3.4% | Nov 6, 2020 | Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl... |
| CVE-2020-5647 | CRITICAL | 9.8 | 4.2% | Nov 6, 2020 | Improper access control vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT14... |
| CVE-2020-5644 | CRITICAL | 9.8 | 4.5% | Nov 6, 2020 | Buffer overflow vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE... |
| CVE-2020-17510 | CRITICAL | 9.8 | 9.1% | Nov 5, 2020 | Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentica... |
| CVE-2020-12145 | CRITICAL | 9.8 | 6.0% | Nov 5, 2020 | Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API... |
| CVE-2020-27955 | CRITICAL | 9.8 | 82.7% | Nov 5, 2020 | Git LFS 2.12.0 allows Remote Code Execution. |
| CVE-2020-15952 | CRITICAL | 9 | 1.5% | Nov 5, 2020 | Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permi... |
| CVE-2020-7128 | CRITICAL | 9.8 | 2.1% | Nov 4, 2020 | A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Pri... |
| CVE-2020-27689 | CRITICAL | 9.8 | 2.2% | Nov 4, 2020 | The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credential... |
| CVE-2020-22274 | CRITICAL | 9.8 | 1.6% | Nov 4, 2020 | JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile. |
| CVE-2020-26167 | CRITICAL | 9.8 | 3.5% | Nov 4, 2020 | In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any acco... |
| CVE-2020-22276 | CRITICAL | 9.8 | 3.0% | Nov 4, 2020 | WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. |
| CVE-2020-2301 | CRITICAL | 9.8 | 1.7% | Nov 4, 2020 | Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a succes... |
| CVE-2020-2300 | CRITICAL | 9.8 | 1.7% | Nov 4, 2020 | Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, wh... |
| CVE-2020-2299 | CRITICAL | 9.8 | 1.3% | Nov 4, 2020 | Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as t... |
| CVE-2020-1909 | CRITICAL | 9.8 | 2.2% | Nov 3, 2020 | A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.2... |
| CVE-2020-16011 | CRITICAL | 9.6 | 2.4% | Nov 3, 2020 | Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromi... |
| CVE-2020-16010 | CRITICAL | 9.6 | 6.4% | Nov 3, 2020 | Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromi... |
| CVE-2020-15999 | CRITICAL | 9.6 | 50.6% | Nov 3, 2020 | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi... |
| CVE-2020-15993 | CRITICAL | 9.8 | 1.1% | Nov 3, 2020 | Use after free in printing in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap ... |
| CVE-2020-5656 | CRITICAL | 9.8 | 2.9% | Nov 2, 2020 | Improper access control vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 Ether... |
| CVE-2020-5653 | CRITICAL | 9.8 | 3.2% | Nov 2, 2020 | Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP N... |
| CVE-2020-28039 | CRITICAL | 9.1 | 4.1% | Nov 2, 2020 | is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not p... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now