2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13818 | HIGH | 7.5 | 37.0% | Jun 4, 2020 | In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed. |
| CVE-2020-13817 | HIGH | 7.4 | 4.1% | Jun 4, 2020 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit o... |
| CVE-2020-13777 | HIGH | 7.4 | 17.5% | Jun 4, 2020 | GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS... |
| CVE-2020-10549 | CRITICAL | 9.8 | 36.2% | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' pass... |
| CVE-2020-10548 | CRITICAL | 9.8 | 36.1% | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passw... |
| CVE-2020-10547 | CRITICAL | 9.8 | 36.1% | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by defa... |
| CVE-2020-10546 | CRITICAL | 9.8 | 87.3% | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, n... |
| CVE-2020-7030 | MEDIUM | 5.5 | 1.0% | Jun 4, 2020 | A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may pot... |
| CVE-2020-11094 | CRITICAL | 9.8 | 1.0% | Jun 4, 2020 | The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all informat... |
| CVE-2020-6504 | MEDIUM | 4.3 | 0.5% | Jun 3, 2020 | Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to by... |
| CVE-2020-6503 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtai... |
| CVE-2020-6502 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof securi... |
| CVE-2020-6501 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass conten... |
| CVE-2020-6500 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof ... |
| CVE-2020-6499 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppC... |
| CVE-2020-6498 | MEDIUM | 6.5 | 0.9% | Jun 3, 2020 | Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to pe... |
| CVE-2020-6497 | MEDIUM | 6.5 | 0.8% | Jun 3, 2020 | Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to pe... |
| CVE-2020-6496 | HIGH | 8.8 | 1.4% | Jun 3, 2020 | Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perf... |
| CVE-2020-6495 | MEDIUM | 6.5 | 1.1% | Jun 3, 2020 | Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convin... |
| CVE-2020-6494 | MEDIUM | 6.5 | 1.5% | Jun 3, 2020 | Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof t... |
| CVE-2020-6493 | CRITICAL | 9.6 | 1.7% | Jun 3, 2020 | Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised... |
| CVE-2020-6453 | HIGH | 8.8 | 0.9% | Jun 3, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially expl... |
| CVE-2020-6419 | HIGH | 8.8 | 0.7% | Jun 3, 2020 | Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap c... |
| CVE-2020-11091 | MEDIUM | 5.8 | 0.9% | Jun 3, 2020 | In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS re... |
| CVE-2020-11080 | HIGH | 7.5 | 5.3% | Jun 3, 2020 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now