2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3481 | HIGH | 7.5 | 3.2% | Jul 20, 2020 | A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could a... |
| CVE-2020-15123 | CRITICAL | 9.3 | 3.8% | Jul 20, 2020 | In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the co... |
| CVE-2020-15121 | CRITICAL | 9.6 | 1.6% | Jul 20, 2020 | In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the p... |
| CVE-2020-15118 | MEDIUM | 5.4 | 1.1% | Jul 20, 2020 | In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagt... |
| CVE-2020-15111 | MEDIUM | 5.4 | 0.9% | Jul 20, 2020 | In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is... |
| CVE-2020-15053 | MEDIUM | 6.1 | 1.8% | Jul 20, 2020 | An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time ... |
| CVE-2020-15052 | HIGH | 7.5 | 2.2% | Jul 20, 2020 | An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alia... |
| CVE-2020-8214 | HIGH | 7.5 | 2.0% | Jul 20, 2020 | A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file. |
| CVE-2020-7680 | MEDIUM | 6.1 | 4.5% | Jul 20, 2020 | docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a... |
| CVE-2020-12031 | HIGH | 7.8 | 0.6% | Jul 20, 2020 | In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a lo... |
| CVE-2020-12028 | HIGH | 8.1 | 51.0% | Jul 20, 2020 | In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to int... |
| CVE-2020-12027 | MEDIUM | 4.3 | 53.0% | Jul 20, 2020 | All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote,... |
| CVE-2020-8215 | HIGH | 8.8 | 2.3% | Jul 20, 2020 | A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitra... |
| CVE-2020-8205 | HIGH | 7.5 | 1.2% | Jul 20, 2020 | The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, w... |
| CVE-2020-14494 | CRITICAL | 9.8 | 1.3% | Jul 20, 2020 | OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide ... |
| CVE-2020-14491 | MEDIUM | 6.5 | 0.8% | Jul 20, 2020 | OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may al... |
| CVE-2020-14485 | CRITICAL | 9.8 | 2.5% | Jul 20, 2020 | OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted... |
| CVE-2020-14484 | CRITICAL | 9.8 | 1.2% | Jul 20, 2020 | OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, whi... |
| CVE-2020-12029 | HIGH | 7.8 | 45.0% | Jul 20, 2020 | All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, un... |
| CVE-2020-4527 | MEDIUM | 5.9 | 1.3% | Jul 20, 2020 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t... |
| CVE-2020-4466 | MEDIUM | 6.5 | 1.4% | Jul 20, 2020 | IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attacker could cause a denial of service due t... |
| CVE-2020-4361 | MEDIUM | 4.3 | 1.0% | Jul 20, 2020 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addres... |
| CVE-2020-15009 | HIGH | 7.8 | 0.4% | Jul 20, 2020 | AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs ... |
| CVE-2020-15842 | HIGH | 8.1 | 1.8% | Jul 20, 2020 | Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, ... |
| CVE-2020-15841 | HIGH | 8.8 | 1.5% | Jul 20, 2020 | Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now