2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15702 | HIGH | 7 | 0.5% | Aug 6, 2020 | TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code.... |
| CVE-2020-15701 | MEDIUM | 5.5 | 0.4% | Aug 6, 2020 | An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of ... |
| CVE-2020-15136 | MEDIUM | 6.5 | 1.6% | Aug 6, 2020 | In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV r... |
| CVE-2020-15114 | HIGH | 7.7 | 1.2% | Aug 6, 2020 | In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery a... |
| CVE-2020-11937 | MEDIUM | 5.5 | 0.5% | Aug 6, 2020 | In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The... |
| CVE-2020-15115 | HIGH | 7.5 | 1.3% | Aug 6, 2020 | etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short pass... |
| CVE-2020-16229 | HIGH | 7.8 | 2.9% | Aug 6, 2020 | Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper... |
| CVE-2020-16217 | HIGH | 7.8 | 2.9% | Aug 6, 2020 | Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing speciall... |
| CVE-2020-16215 | HIGH | 7.8 | 4.0% | Aug 6, 2020 | Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper... |
| CVE-2020-16213 | HIGH | 7.8 | 3.0% | Aug 6, 2020 | Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper... |
| CVE-2020-16211 | MEDIUM | 5.5 | 1.3% | Aug 6, 2020 | Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by p... |
| CVE-2020-16207 | HIGH | 7.8 | 3.7% | Aug 6, 2020 | Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may b... |
| CVE-2020-13793 | CRITICAL | 9.8 | 1.7% | Aug 6, 2020 | Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key. |
| CVE-2020-12441 | CRITICAL | 9.8 | 3.8% | Aug 6, 2020 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parse... |
| CVE-2020-16845 | HIGH | 7.5 | 4.7% | Aug 6, 2020 | Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary... |
| CVE-2020-7817 | HIGH | 7.8 | 0.3% | Aug 6, 2020 | MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a... |
| CVE-2020-7460 | HIGH | 7 | 0.7% | Aug 6, 2020 | In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 1... |
| CVE-2020-7459 | MEDIUM | 6.8 | 0.4% | Aug 6, 2020 | In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 1... |
| CVE-2020-13365 | HIGH | 8.8 | 1.0% | Aug 6, 2020 | Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocu... |
| CVE-2020-13364 | HIGH | 8.8 | 1.2% | Aug 6, 2020 | A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, ... |
| CVE-2020-7361 | HIGH | 8.8 | 17.2% | Aug 6, 2020 | The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' co... |
| CVE-2020-7357 | CRITICAL | 9.9 | 33.9% | Aug 6, 2020 | Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This ca... |
| CVE-2020-7356 | CRITICAL | 9.8 | 14.0% | Aug 6, 2020 | CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_s... |
| CVE-2020-7352 | HIGH | 8.8 | 3.8% | Aug 6, 2020 | The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to th... |
| CVE-2020-9036 | MEDIUM | 6.1 | 3.6% | Aug 5, 2020 | Jeedom through 4.0.38 allows XSS. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now