2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24381 | HIGH | 7.5 | 1.4% | Aug 19, 2020 | GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessm... |
| CVE-2020-5385 | HIGH | 7.8 | 0.2% | Aug 18, 2020 | Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escala... |
| CVE-2020-24032 | CRITICAL | 9.8 | 5.4% | Aug 18, 2020 | tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharac... |
| CVE-2020-23934 | HIGH | 8.8 | 16.0% | Aug 18, 2020 | An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php ... |
| CVE-2020-15926 | MEDIUM | 6.1 | 2.8% | Aug 18, 2020 | Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct ... |
| CVE-2020-15865 | CRITICAL | 9.8 | 5.1% | Aug 18, 2020 | A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode ... |
| CVE-2020-9415 | MEDIUM | 6.5 | 0.8% | Aug 18, 2020 | The TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtual... |
| CVE-2020-23933 | — | — | — | Aug 18, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-7019 | MEDIUM | 6.5 | 1.2% | Aug 18, 2020 | In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Le... |
| CVE-2020-7018 | HIGH | 8.8 | 1.1% | Aug 18, 2020 | Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is give... |
| CVE-2020-24212 | — | — | — | Aug 18, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. This candidate was erroneously published without a public reference c... |
| CVE-2020-23938 | — | — | — | Aug 18, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. This candidate was erroneously published without a public reference c... |
| CVE-2020-14936 | CRITICAL | 9.8 | 1.4% | Aug 18, 2020 | Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. Functions parsing the OIDs in SNMP re... |
| CVE-2020-14935 | CRITICAL | 9.8 | 2.5% | Aug 18, 2020 | Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function.... |
| CVE-2020-14934 | CRITICAL | 9.8 | 1.5% | Aug 18, 2020 | Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. The function parsing the received SNM... |
| CVE-2020-14937 | CRITICAL | 9.1 | 1.5% | Aug 18, 2020 | Memory access out of buffer boundaries issues was discovered in Contiki-NG 4.4 through 4.5, in the SNMP BER encoder/deco... |
| CVE-2020-7708 | CRITICAL | 9.8 | 2.8% | Aug 18, 2020 | The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via ... |
| CVE-2020-7707 | CRITICAL | 9.8 | 3.4% | Aug 18, 2020 | The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function. |
| CVE-2020-14333 | MEDIUM | 6.1 | 0.8% | Aug 18, 2020 | A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable par... |
| CVE-2020-7706 | CRITICAL | 9.8 | 2.8% | Aug 18, 2020 | The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by... |
| CVE-2020-15152 | CRITICAL | 9.1 | 1.9% | Aug 17, 2020 | ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv... |
| CVE-2020-13933 | HIGH | 7.5 | 48.0% | Aug 17, 2020 | Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass. |
| CVE-2020-13183 | MEDIUM | 6.1 | 0.6% | Aug 17, 2020 | Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over ... |
| CVE-2020-12480 | MEDIUM | 6.5 | 0.5% | Aug 17, 2020 | In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types... |
| CVE-2020-1597 | HIGH | 7.5 | 6.6% | Aug 17, 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now