2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14158 | CRITICAL | 9.1 | 1.8% | Jul 30, 2020 | The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity ... |
| CVE-2020-12620 | HIGH | 7.8 | 1.5% | Jul 30, 2020 | Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection... |
| CVE-2020-8222 | MEDIUM | 6.8 | 2.3% | Jul 30, 2020 | A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the admi... |
| CVE-2020-8221 | MEDIUM | 4.9 | 2.3% | Jul 30, 2020 | A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbi... |
| CVE-2020-8220 | MEDIUM | 6.5 | 2.5% | Jul 30, 2020 | A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform... |
| CVE-2020-8219 | HIGH | 7.2 | 2.2% | Jul 30, 2020 | An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change t... |
| CVE-2020-8218 | HIGH | 7.2 | 32.7% | Jul 30, 2020 | A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform... |
| CVE-2020-8217 | MEDIUM | 5.4 | 1.4% | Jul 30, 2020 | A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used f... |
| CVE-2020-8216 | MEDIUM | 4.3 | 2.3% | Jul 30, 2020 | An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to ... |
| CVE-2020-8213 | MEDIUM | 5.3 | 1.1% | Jul 30, 2020 | An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attacke... |
| CVE-2020-8206 | HIGH | 8.1 | 3.0% | Jul 30, 2020 | An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users prim... |
| CVE-2020-8204 | MEDIUM | 6.1 | 1.8% | Jul 30, 2020 | A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page. |
| CVE-2020-8202 | MEDIUM | 5.3 | 1.3% | Jul 30, 2020 | Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when ... |
| CVE-2020-8192 | MEDIUM | 6.5 | 1.2% | Jul 30, 2020 | A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger reso... |
| CVE-2020-4186 | MEDIUM | 5.3 | 1.1% | Jul 30, 2020 | IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in furt... |
| CVE-2020-4185 | HIGH | 7.5 | 0.8% | Jul 30, 2020 | IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attack... |
| CVE-2020-14309 | MEDIUM | 6.7 | 0.5% | Jul 30, 2020 | There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link wi... |
| CVE-2020-10713 | HIGH | 8.2 | 1.1% | Jul 30, 2020 | A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB veri... |
| CVE-2020-3701 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Use after free issue while processing error notification from camx driver due to not properly releasing the sequence dat... |
| CVE-2020-3700 | HIGH | 7.5 | 1.1% | Jul 30, 2020 | Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi dri... |
| CVE-2020-3699 | CRITICAL | 9.8 | 0.9% | Jul 30, 2020 | Possible out of bound access while processing assoc response from host due to improper length check before copying into ... |
| CVE-2020-3698 | CRITICAL | 9.8 | 0.9% | Jul 30, 2020 | Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response f... |
| CVE-2020-3688 | CRITICAL | 9.8 | 0.9% | Jul 30, 2020 | Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapd... |
| CVE-2020-3671 | CRITICAL | 9.8 | 0.9% | Jul 30, 2020 | Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compu... |
| CVE-2020-7699 | CRITICAL | 9.8 | 4.7% | Jul 30, 2020 | This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP r... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now