2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0123 | CRITICAL | 9.8 | 0.6% | Sep 17, 2020 | There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID... |
| CVE-2020-8028 | CRITICAL | 9.3 | 0.4% | Sep 17, 2020 | A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Se... |
| CVE-2020-24377 | CRITICAL | 9.6 | 1.2% | Sep 16, 2020 | A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3. |
| CVE-2020-24376 | CRITICAL | 9.6 | 1.0% | Sep 16, 2020 | A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.... |
| CVE-2020-24374 | CRITICAL | 9.6 | 1.2% | Sep 16, 2020 | A DNS rebinding vulnerability in Freebox v5 before 1.5.29. |
| CVE-2020-14517 | CRITICAL | 9.8 | 0.7% | Sep 16, 2020 | Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 ... |
| CVE-2020-14509 | CRITICAL | 9.8 | 2.0% | Sep 16, 2020 | Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mecha... |
| CVE-2020-25614 | CRITICAL | 9.8 | 1.9% | Sep 16, 2020 | xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause... |
| CVE-2020-25412 | CRITICAL | 9.8 | 2.5% | Sep 16, 2020 | com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code ex... |
| CVE-2020-14315 | CRITICAL | 9.8 | 2.5% | Sep 16, 2020 | A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insuffi... |
| CVE-2020-7293 | CRITICAL | 9 | 0.7% | Sep 15, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user w... |
| CVE-2020-23833 | CRITICAL | 9.8 | 4.2% | Sep 15, 2020 | Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers t... |
| CVE-2020-23828 | CRITICAL | 9.8 | 4.1% | Sep 15, 2020 | A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote ... |
| CVE-2020-24561 | CRITICAL | 9.1 | 5.2% | Sep 15, 2020 | A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrar... |
| CVE-2020-15148 | CRITICAL | 10 | 79.2% | Sep 15, 2020 | Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize(... |
| CVE-2020-15179 | CRITICAL | 9 | 1.2% | Sep 15, 2020 | The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using <script> tag insid... |
| CVE-2020-15178 | CRITICAL | 9.3 | 1.2% | Sep 15, 2020 | In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript... |
| CVE-2020-23512 | CRITICAL | 9.8 | 2.3% | Sep 15, 2020 | VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the ... |
| CVE-2020-16098 | CRITICAL | 9.8 | 1.1% | Sep 15, 2020 | It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions ... |
| CVE-2020-13312 | CRITICAL | 9.8 | 0.9% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerabl... |
| CVE-2020-25576 | CRITICAL | 9.8 | 1.5% | Sep 14, 2020 | An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandle... |
| CVE-2020-25575 | CRITICAL | 9.8 | 2.9% | Sep 14, 2020 | An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some ap... |
| CVE-2020-25573 | CRITICAL | 9.8 | 1.8% | Sep 14, 2020 | An issue was discovered in the linked-hash-map crate before 0.5.3 for Rust. It creates an uninitialized NonNull pointer,... |
| CVE-2020-13300 | CRITICAL | 10 | 1.3% | Sep 14, 2020 | GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in ... |
| CVE-2020-11684 | CRITICAL | 9.1 | 1.1% | Sep 14, 2020 | AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now