2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5131 | HIGH | 7.8 | 0.5% | Jul 17, 2020 | SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite... |
| CVE-2020-5130 | MEDIUM | 5.3 | 1.3% | Jul 17, 2020 | SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper va... |
| CVE-2020-15497 | MEDIUM | 6.1 | 1.3% | Jul 17, 2020 | jcore/portal/ajaxPortal.jsp in Jalios JCMS 10.0.2 build-20200224104759 allows XSS via the types parameter. Note: It is a... |
| CVE-2020-7826 | CRITICAL | 9.8 | 0.7% | Jul 17, 2020 | EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be ... |
| CVE-2020-7825 | CRITICAL | 9.8 | 2.1% | Jul 17, 2020 | A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05... |
| CVE-2020-15807 | MEDIUM | 6.5 | 1.5% | Jul 17, 2020 | GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files. |
| CVE-2020-15586 | MEDIUM | 5.9 | 2.9% | Jul 17, 2020 | Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.Rev... |
| CVE-2020-14928 | MEDIUM | 5.9 | 2.8% | Jul 17, 2020 | evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server send... |
| CVE-2020-14039 | MEDIUM | 5.3 | 1.8% | Jul 17, 2020 | In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU re... |
| CVE-2020-14001 | CRITICAL | 9.8 | 4.5% | Jul 17, 2020 | The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows ... |
| CVE-2020-4464 | HIGH | 8.8 | 13.2% | Jul 17, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary c... |
| CVE-2020-7696 | MEDIUM | 5.3 | 1.6% | Jul 17, 2020 | This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "... |
| CVE-2020-7684 | CRITICAL | 9.8 | 1.5% | Jul 17, 2020 | This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation. |
| CVE-2020-15803 | MEDIUM | 6.1 | 32.3% | Jul 17, 2020 | Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stor... |
| CVE-2020-15801 | CRITICAL | 9.8 | 3.1% | Jul 17, 2020 | In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from ar... |
| CVE-2020-9688 | HIGH | 7.8 | 4.8% | Jul 17, 2020 | Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to a... |
| CVE-2020-9682 | CRITICAL | 9.8 | 4.3% | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful... |
| CVE-2020-9673 | HIGH | 7.8 | 1.0% | Jul 17, 2020 | Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll searc... |
| CVE-2020-9672 | HIGH | 7.8 | 1.0% | Jul 17, 2020 | Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll searc... |
| CVE-2020-9671 | CRITICAL | 9.8 | 4.0% | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Succe... |
| CVE-2020-9670 | CRITICAL | 9.8 | 3.6% | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful... |
| CVE-2020-9669 | CRITICAL | 9.8 | 3.4% | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Succ... |
| CVE-2020-9650 | HIGH | 7.8 | 3.3% | Jul 17, 2020 | Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l... |
| CVE-2020-9649 | MEDIUM | 5.5 | 2.6% | Jul 17, 2020 | Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could le... |
| CVE-2020-9646 | HIGH | 7.8 | 3.2% | Jul 17, 2020 | Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now