2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8226 | MEDIUM | 5.8 | 1.0% | Aug 17, 2020 | A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF. |
| CVE-2020-8212 | CRITICAL | 9.8 | 1.6% | Aug 17, 2020 | Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix Xe... |
| CVE-2020-8211 | CRITICAL | 9.8 | 1.5% | Aug 17, 2020 | Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix ... |
| CVE-2020-8210 | HIGH | 7.5 | 1.5% | Aug 17, 2020 | Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6... |
| CVE-2020-8209 | HIGH | 7.5 | 48.7% | Aug 17, 2020 | Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe... |
| CVE-2020-8208 | MEDIUM | 6.1 | 1.0% | Aug 17, 2020 | Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix ... |
| CVE-2020-13122 | HIGH | 8.8 | 7.1% | Aug 17, 2020 | The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, i... |
| CVE-2020-9242 | HIGH | 8.8 | 1.3% | Aug 17, 2020 | FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain paramete... |
| CVE-2020-9103 | MEDIUM | 4.6 | 0.2% | Aug 17, 2020 | HUAWEI Mate 20 smartphones with 9.0.0.205(C00E205R2P1) have a logic error vulnerability. In a special scenario, the syst... |
| CVE-2020-7703 | CRITICAL | 9.8 | 1.9% | Aug 17, 2020 | All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function. |
| CVE-2020-7702 | CRITICAL | 9.8 | 1.9% | Aug 17, 2020 | All versions of package templ8 are vulnerable to Prototype Pollution via the parse function. |
| CVE-2020-12606 | CRITICAL | 9.8 | 3.4% | Aug 17, 2020 | An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webs... |
| CVE-2020-4686 | HIGH | 8.1 | 1.6% | Aug 17, 2020 | IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform ... |
| CVE-2020-13941 | HIGH | 8.8 | 3.8% | Aug 17, 2020 | Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handl... |
| CVE-2020-24361 | CRITICAL | 9.8 | 2.0% | Aug 16, 2020 | SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec. |
| CVE-2020-17475 | HIGH | 7.5 | 0.9% | Aug 14, 2020 | Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to... |
| CVE-2020-17474 | CRITICAL | 9.8 | 1.2% | Aug 14, 2020 | A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to... |
| CVE-2020-17473 | MEDIUM | 5.9 | 0.7% | Aug 14, 2020 | Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker ... |
| CVE-2020-17464 | — | — | — | Aug 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-14353 | — | — | — | Aug 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-18270. Reason: This candidate is a duplicate of ... |
| CVE-2020-0255 | — | — | — | Aug 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10751. Reason: This candidate is a duplicate of ... |
| CVE-2020-15694 | HIGH | 7.5 | 2.3% | Aug 14, 2020 | In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.ge... |
| CVE-2020-15693 | MEDIUM | 6.5 | 2.0% | Aug 14, 2020 | In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is poss... |
| CVE-2020-15692 | CRITICAL | 9.8 | 4.2% | Aug 14, 2020 | In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument ca... |
| CVE-2020-9767 | HIGH | 7.8 | 0.8% | Aug 14, 2020 | A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now