2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7746 | CRITICAL | 9.8 | 4.7% | Oct 29, 2020 | This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. Wh... |
| CVE-2020-11486 | CRITICAL | 9.8 | 2.6% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmwa... |
| CVE-2020-11483 | CRITICAL | 9.8 | 1.4% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior... |
| CVE-2020-27739 | CRITICAL | 9.8 | 1.8% | Oct 28, 2020 | A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack ... |
| CVE-2020-16263 | CRITICAL | 9.1 | 1.2% | Oct 28, 2020 | Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewe... |
| CVE-2020-16259 | CRITICAL | 9.8 | 1.7% | Oct 28, 2020 | Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents ... |
| CVE-2020-16257 | CRITICAL | 9.8 | 3.7% | Oct 28, 2020 | Winston 1.5.4 devices are vulnerable to command injection via the API. |
| CVE-2020-27976 | CRITICAL | 9.8 | 7.0% | Oct 28, 2020 | osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter ... |
| CVE-2020-8239 | CRITICAL | 9.8 | 2.0% | Oct 28, 2020 | A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation att... |
| CVE-2020-27956 | CRITICAL | 9.8 | 5.2% | Oct 28, 2020 | An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the use... |
| CVE-2020-9866 | CRITICAL | 9.8 | 1.9% | Oct 27, 2020 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.6, Security U... |
| CVE-2020-27160 | CRITICAL | 9.8 | 4.7% | Oct 27, 2020 | Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digi... |
| CVE-2020-27159 | CRITICAL | 9.8 | 5.9% | Oct 27, 2020 | Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validat... |
| CVE-2020-27158 | CRITICAL | 9.8 | 7.2% | Oct 27, 2020 | Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My... |
| CVE-2020-25765 | CRITICAL | 9.8 | 5.8% | Oct 27, 2020 | Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western ... |
| CVE-2020-12830 | CRITICAL | 9.8 | 3.2% | Oct 27, 2020 | Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privile... |
| CVE-2020-27853 | CRITICAL | 9.8 | 3.8% | Oct 27, 2020 | Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbi... |
| CVE-2020-11854 | CRITICAL | 9.8 | 74.2% | Oct 27, 2020 | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bri... |
| CVE-2020-10256 | CRITICAL | 9.8 | 0.9% | Oct 27, 2020 | An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1... |
| CVE-2020-27183 | CRITICAL | 9.8 | 1.3% | Oct 27, 2020 | A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to discl... |
| CVE-2020-27179 | CRITICAL | 9.8 | 1.3% | Oct 27, 2020 | konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset to... |
| CVE-2020-27743 | CRITICAL | 9.8 | 1.7% | Oct 26, 2020 | libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to ... |
| CVE-2020-26879 | CRITICAL | 9.8 | 42.5% | Oct 26, 2020 | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacke... |
| CVE-2020-15272 | CRITICAL | 9.6 | 1.2% | Oct 26, 2020 | In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*)... |
| CVE-2020-7197 | CRITICAL | 9.8 | 2.2% | Oct 26, 2020 | SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off nod... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now