2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15889 | CRITICAL | 9.8 | 2.2% | Jul 21, 2020 | Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient... |
| CVE-2020-15888 | HIGH | 8.8 | 2.4% | Jul 21, 2020 | Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffe... |
| CVE-2020-15724 | HIGH | 7.8 | 0.6% | Jul 21, 2020 | In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a loca... |
| CVE-2020-15723 | HIGH | 7.8 | 0.5% | Jul 21, 2020 | In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome... |
| CVE-2020-15722 | HIGH | 7.8 | 0.4% | Jul 21, 2020 | In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privileg... |
| CVE-2020-15102 | MEDIUM | 6.5 | 0.7% | Jul 21, 2020 | In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to c... |
| CVE-2020-14063 | MEDIUM | 6.1 | 1.4% | Jul 21, 2020 | A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows u... |
| CVE-2020-15879 | HIGH | 7.5 | 2.7% | Jul 21, 2020 | Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe,... |
| CVE-2020-15877 | HIGH | 8.8 | 1.9% | Jul 21, 2020 | An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guar... |
| CVE-2020-15873 | MEDIUM | 6.5 | 2.2% | Jul 21, 2020 | In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST ... |
| CVE-2020-15859 | LOW | 3.3 | 0.4% | Jul 21, 2020 | QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the da... |
| CVE-2020-15866 | CRITICAL | 9.8 | 2.1% | Jul 21, 2020 | mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrec... |
| CVE-2020-12499 | HIGH | 7.3 | 0.4% | Jul 21, 2020 | In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on imp... |
| CVE-2020-12432 | MEDIUM | 6.1 | 0.9% | Jul 21, 2020 | The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a... |
| CVE-2020-4125 | HIGH | 8.1 | 0.4% | Jul 20, 2020 | Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL enviro... |
| CVE-2020-13932 | MEDIUM | 6.1 | 4.3% | Jul 20, 2020 | In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or top... |
| CVE-2020-6103 | CRITICAL | 9.9 | 2.8% | Jul 20, 2020 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.... |
| CVE-2020-6102 | CRITICAL | 9.9 | 2.8% | Jul 20, 2020 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.... |
| CVE-2020-6101 | CRITICAL | 9.9 | 2.8% | Jul 20, 2020 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.... |
| CVE-2020-6100 | CRITICAL | 9.9 | 2.1% | Jul 20, 2020 | An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially... |
| CVE-2020-3442 | MEDIUM | 5.7 | 0.2% | Jul 20, 2020 | The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initi... |
| CVE-2020-1776 | MEDIUM | 4.3 | 0.9% | Jul 20, 2020 | When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not b... |
| CVE-2020-15852 | HIGH | 7.8 | 0.3% | Jul 20, 2020 | An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attac... |
| CVE-2020-6872 | MEDIUM | 6.1 | 0.7% | Jul 20, 2020 | The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes thr... |
| CVE-2020-6871 | CRITICAL | 9.8 | 1.9% | Jul 20, 2020 | The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now