2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13554 | HIGH | 7.8 | 0.5% | Mar 3, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD... |
| CVE-2020-35296 | HIGH | 7.5 | 2.2% | Mar 3, 2021 | ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboar... |
| CVE-2020-10519 | HIGH | 8.8 | 3.0% | Mar 3, 2021 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a... |
| CVE-2020-12528 | HIGH | 7.7 | 0.8% | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improp... |
| CVE-2020-35662 | HIGH | 7.4 | 3.0% | Feb 27, 2021 | In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not alway... |
| CVE-2020-28243 | HIGH | 7.8 | 4.3% | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection vi... |
| CVE-2020-36079 | HIGH | 7.2 | 4.7% | Feb 26, 2021 | Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacke... |
| CVE-2020-24686 | HIGH | 7.5 | 1.4% | Feb 26, 2021 | The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leadin... |
| CVE-2020-28646 | HIGH | 7.8 | 0.8% | Feb 26, 2021 | ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain dir... |
| CVE-2020-17162 | HIGH | 8.8 | 2.2% | Feb 25, 2021 | Microsoft Windows Security Feature Bypass Vulnerability |
| CVE-2020-27543 | HIGH | 7.5 | 2.6% | Feb 25, 2021 | The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP... |
| CVE-2020-8032 | HIGH | 7 | 0.4% | Feb 25, 2021 | A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to esc... |
| CVE-2020-36254 | HIGH | 8.1 | 1.6% | Feb 25, 2021 | scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685. |
| CVE-2020-11988 | HIGH | 8.2 | 6.7% | Feb 24, 2021 | Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input valida... |
| CVE-2020-11987 | HIGH | 8.2 | 13.6% | Feb 24, 2021 | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPan... |
| CVE-2020-7836 | HIGH | 7.8 | 0.6% | Feb 24, 2021 | VOICEYE WSActiveBridgeES versions prior to 2.1.0.3 contains a stack-based buffer overflow vulnerability caused by improp... |
| CVE-2020-7846 | HIGH | 8.8 | 1.0% | Feb 24, 2021 | Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key.... |
| CVE-2020-28599 | HIGH | 7.8 | 2.0% | Feb 24, 2021 | A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-... |
| CVE-2020-28587 | HIGH | 7.8 | 0.9% | Feb 23, 2021 | A specially crafted document can cause the document parser to copy data from a particular record type into a static-size... |
| CVE-2020-27782 | HIGH | 7.5 | 1.3% | Feb 23, 2021 | A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an... |
| CVE-2020-25161 | HIGH | 8.8 | 1.5% | Feb 23, 2021 | The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path... |
| CVE-2020-16243 | HIGH | 7.8 | 12.0% | Feb 23, 2021 | Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. ... |
| CVE-2020-7847 | HIGH | 8 | 0.5% | Feb 23, 2021 | The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can b... |
| CVE-2020-14359 | HIGH | 7.3 | 0.9% | Feb 23, 2021 | A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an a... |
| CVE-2020-25690 | HIGH | 8.8 | 1.3% | Feb 23, 2021 | An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certai... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now