2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5610 | HIGH | 7.8 | 1.4% | Jul 30, 2020 | Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service... |
| CVE-2020-16143 | HIGH | 7.8 | 0.4% | Jul 29, 2020 | The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current... |
| CVE-2020-16135 | MEDIUM | 5.9 | 4.1% | Jul 29, 2020 | libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL. |
| CVE-2020-14308 | MEDIUM | 6.4 | 0.4% | Jul 29, 2020 | In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested... |
| CVE-2020-5763 | HIGH | 8.8 | 2.7% | Jul 29, 2020 | Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated rem... |
| CVE-2020-5762 | HIGH | 7.5 | 3.4% | Jul 29, 2020 | Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-... |
| CVE-2020-5761 | HIGH | 7.5 | 4.1% | Jul 29, 2020 | Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in ... |
| CVE-2020-5760 | HIGH | 7.8 | 5.5% | Jul 29, 2020 | Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Una... |
| CVE-2020-14316 | CRITICAL | 9.9 | 1.6% | Jul 29, 2020 | A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's... |
| CVE-2020-16118 | HIGH | 7.5 | 2.1% | Jul 29, 2020 | In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and... |
| CVE-2020-16117 | MEDIUM | 5.9 | 2.2% | Jul 29, 2020 | In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer derefere... |
| CVE-2020-15707 | MEDIUM | 6.4 | 1.6% | Jul 29, 2020 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRU... |
| CVE-2020-15706 | MEDIUM | 6.4 | 1.0% | Jul 29, 2020 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be ... |
| CVE-2020-15705 | MEDIUM | 6.4 | 1.4% | Jul 29, 2020 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This on... |
| CVE-2020-15588 | CRITICAL | 9.8 | 12.7% | Jul 29, 2020 | An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled serve... |
| CVE-2020-15125 | HIGH | 7.7 | 1.5% | Jul 29, 2020 | In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request obj... |
| CVE-2020-15099 | HIGH | 8.1 | 1.8% | Jul 29, 2020 | In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4... |
| CVE-2020-15098 | HIGH | 8.8 | 2.2% | Jul 29, 2020 | In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4... |
| CVE-2020-15086 | CRITICAL | 9.8 | 2.7% | Jul 29, 2020 | In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered ... |
| CVE-2020-11934 | MEDIUM | 5.9 | 0.4% | Jul 29, 2020 | It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the syste... |
| CVE-2020-11933 | MEDIUM | 6.8 | 0.2% | Jul 29, 2020 | cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, ... |
| CVE-2020-13699 | HIGH | 8.8 | 25.9% | Jul 29, 2020 | TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could ... |
| CVE-2020-8553 | MEDIUM | 5.9 | 0.9% | Jul 29, 2020 | The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and t... |
| CVE-2020-16095 | MEDIUM | 6.1 | 0.9% | Jul 29, 2020 | The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS. |
| CVE-2020-4645 | MEDIUM | 5.4 | 0.6% | Jul 29, 2020 | IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows user... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now