2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28037 | CRITICAL | 9.8 | 7.7% | Nov 2, 2020 | is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is alre... |
| CVE-2020-28036 | CRITICAL | 9.8 | 5.2% | Nov 2, 2020 | wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to... |
| CVE-2020-28035 | CRITICAL | 9.8 | 4.2% | Nov 2, 2020 | WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. |
| CVE-2020-28032 | CRITICAL | 9.8 | 16.1% | Nov 2, 2020 | WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. |
| CVE-2020-24881 | CRITICAL | 9.8 | 73.3% | Nov 2, 2020 | SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. |
| CVE-2020-23639 | CRITICAL | 9.8 | 3.1% | Nov 2, 2020 | A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a r... |
| CVE-2020-14750 | CRITICAL | 9.8 | 99.3% | Nov 2, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions... |
| CVE-2020-3703 | CRITICAL | 9.8 | 0.7% | Nov 2, 2020 | u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode r... |
| CVE-2020-3692 | CRITICAL | 9.8 | 0.9% | Nov 2, 2020 | u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input valid... |
| CVE-2020-3673 | CRITICAL | 9.8 | 1.0% | Nov 2, 2020 | u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check... |
| CVE-2020-3670 | CRITICAL | 9.1 | 0.9% | Nov 2, 2020 | u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Informati... |
| CVE-2020-3657 | CRITICAL | 9.8 | 28.3% | Nov 2, 2020 | u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from ... |
| CVE-2020-3654 | CRITICAL | 9.8 | 0.9% | Nov 2, 2020 | u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying int... |
| CVE-2020-11172 | CRITICAL | 9.8 | 0.7% | Nov 2, 2020 | u'fscanf reads a string from a file and stores its contents on a statically allocated stack memory which leads to stack ... |
| CVE-2020-11169 | CRITICAL | 9.1 | 0.8% | Nov 2, 2020 | u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Sna... |
| CVE-2020-11153 | CRITICAL | 9.8 | 2.2% | Nov 2, 2020 | u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to re... |
| CVE-2020-7373 | CRITICAL | 9.8 | 46.0% | Oct 30, 2020 | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe... |
| CVE-2020-27886 | CRITICAL | 9.8 | 1.7% | Oct 29, 2020 | An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injectio... |
| CVE-2020-27998 | CRITICAL | 9.8 | 2.3% | Oct 29, 2020 | An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (fo... |
| CVE-2020-27995 | CRITICAL | 9.8 | 8.7% | Oct 29, 2020 | SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the se... |
| CVE-2020-27744 | CRITICAL | 9.8 | 5.9% | Oct 29, 2020 | An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with r... |
| CVE-2020-27655 | CRITICAL | 10 | 1.7% | Oct 29, 2020 | Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to acce... |
| CVE-2020-27654 | CRITICAL | 9.8 | 4.6% | Oct 29, 2020 | Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers ... |
| CVE-2020-27649 | CRITICAL | 9 | 0.7% | Oct 29, 2020 | Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allow... |
| CVE-2020-27648 | CRITICAL | 9 | 0.7% | Oct 29, 2020 | Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now