2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4965 | HIGH | 7.5 | 0.7% | Apr 12, 2021 | IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt ... |
| CVE-2020-24285 | HIGH | 7.5 | 4.7% | Apr 12, 2021 | INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgi... |
| CVE-2020-36317 | HIGH | 7.5 | 1.5% | Apr 11, 2021 | In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation ... |
| CVE-2020-13592 | HIGH | 8.8 | 1.5% | Apr 9, 2021 | An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management A... |
| CVE-2020-13591 | HIGH | 8.8 | 1.5% | Apr 9, 2021 | An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Manag... |
| CVE-2020-13587 | HIGH | 8.8 | 1.5% | Apr 9, 2021 | An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Mana... |
| CVE-2020-13534 | HIGH | 7.8 | 0.9% | Apr 9, 2021 | A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream R... |
| CVE-2020-13533 | HIGH | 7.8 | 0.4% | Apr 9, 2021 | A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following regist... |
| CVE-2020-13532 | HIGH | 7.8 | 0.4% | Apr 9, 2021 | A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashbo... |
| CVE-2020-21884 | HIGH | 8.8 | 1.2% | Apr 9, 2021 | Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF)... |
| CVE-2020-21883 | HIGH | 8.8 | 6.0% | Apr 9, 2021 | Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerabili... |
| CVE-2020-6590 | HIGH | 7.5 | 1.0% | Apr 8, 2021 | Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information dis... |
| CVE-2020-14104 | HIGH | 8.1 | 0.7% | Apr 8, 2021 | A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50. |
| CVE-2020-14099 | HIGH | 7.5 | 0.6% | Apr 8, 2021 | On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backu... |
| CVE-2020-23539 | HIGH | 7.5 | 1.8% | Apr 8, 2021 | An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service ... |
| CVE-2020-24140 | HIGH | 8.3 | 1.2% | Apr 7, 2021 | Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable... |
| CVE-2020-24139 | HIGH | 8.3 | 1.1% | Apr 7, 2021 | Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerabl... |
| CVE-2020-25584 | HIGH | 7.5 | 0.2% | Apr 7, 2021 | In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-... |
| CVE-2020-24136 | HIGH | 8.6 | 2.2% | Apr 7, 2021 | Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an applicatio... |
| CVE-2020-11255 | HIGH | 7.5 | 0.7% | Apr 7, 2021 | Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is f... |
| CVE-2020-11246 | HIGH | 7.8 | 0.2% | Apr 7, 2021 | A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapd... |
| CVE-2020-11245 | HIGH | 7.8 | 0.2% | Apr 7, 2021 | Unintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Au... |
| CVE-2020-11243 | HIGH | 7.5 | 0.7% | Apr 7, 2021 | RRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to... |
| CVE-2020-11242 | HIGH | 7.8 | 0.2% | Apr 7, 2021 | User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to captu... |
| CVE-2020-11237 | HIGH | 7.8 | 0.2% | Apr 7, 2021 | Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before access... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now