2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15073 | MEDIUM | 5.4 | 0.7% | Jul 8, 2020 | An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section v... |
| CVE-2020-15072 | HIGH | 8.8 | 1.2% | Jul 8, 2020 | An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Admin... |
| CVE-2020-2034 | HIGH | 8.1 | 6.6% | Jul 8, 2020 | An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacke... |
| CVE-2020-2031 | MEDIUM | 4.9 | 1.1% | Jul 8, 2020 | An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated ad... |
| CVE-2020-2030 | HIGH | 7.2 | 2.5% | Jul 8, 2020 | An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to exe... |
| CVE-2020-1982 | MEDIUM | 4.8 | 0.4% | Jul 8, 2020 | Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryp... |
| CVE-2020-6938 | HIGH | 7.5 | 1.2% | Jul 8, 2020 | A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26,... |
| CVE-2020-5839 | HIGH | 7.5 | 2.0% | Jul 8, 2020 | Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is ... |
| CVE-2020-11994 | HIGH | 7.5 | 4.5% | Jul 8, 2020 | Server-Side Template Injection and arbitrary file disclosure on Camel templating components |
| CVE-2020-14476 | — | — | — | Jul 8, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-7140 | MEDIUM | 6.1 | 0.8% | Jul 8, 2020 | A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a ... |
| CVE-2020-5764 | HIGH | 8.8 | 2.0% | Jul 8, 2020 | MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is usin... |
| CVE-2020-3973 | HIGH | 8.8 | 1.1% | Jul 8, 2020 | The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious act... |
| CVE-2020-11849 | CRITICAL | 9.8 | 1.2% | Jul 8, 2020 | Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prio... |
| CVE-2020-3931 | CRITICAL | 9.8 | 1.8% | Jul 8, 2020 | Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute ar... |
| CVE-2020-15600 | MEDIUM | 6.5 | 1.9% | Jul 7, 2020 | An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password. |
| CVE-2020-8916 | MEDIUM | 5.5 | 0.3% | Jul 7, 2020 | A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an e... |
| CVE-2020-15599 | MEDIUM | 6.1 | 2.1% | Jul 7, 2020 | Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field. |
| CVE-2020-8521 | CRITICAL | 9.8 | 1.4% | Jul 7, 2020 | SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with a... |
| CVE-2020-8520 | CRITICAL | 9.8 | 1.4% | Jul 7, 2020 | SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with aja... |
| CVE-2020-8519 | CRITICAL | 9.8 | 1.4% | Jul 7, 2020 | SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php... |
| CVE-2020-15008 | HIGH | 7.5 | 0.9% | Jul 7, 2020 | A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the pr... |
| CVE-2020-12821 | CRITICAL | 9.8 | 1.9% | Jul 7, 2020 | Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack. |
| CVE-2020-12736 | HIGH | 7.2 | 2.0% | Jul 7, 2020 | Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an... |
| CVE-2020-15095 | MEDIUM | 4.4 | 0.4% | Jul 7, 2020 | Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The C... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now