2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15786 | CRITICAL | 9.8 | 1.5% | Sep 9, 2020 | A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V... |
| CVE-2020-2040 | CRITICAL | 9.8 | 3.9% | Sep 9, 2020 | A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially... |
| CVE-2020-25213 | CRITICAL | 9.8 | 97.3% | Sep 9, 2020 | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra... |
| CVE-2020-11986 | CRITICAL | 9.8 | 9.9% | Sep 9, 2020 | To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This... |
| CVE-2020-24199 | CRITICAL | 9.8 | 3.7% | Sep 9, 2020 | Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows a... |
| CVE-2020-24195 | CRITICAL | 9.1 | 2.9% | Sep 9, 2020 | An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated ad... |
| CVE-2020-24197 | CRITICAL | 9.8 | 1.4% | Sep 9, 2020 | A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute a... |
| CVE-2020-24074 | CRITICAL | 9.8 | 2.0% | Sep 9, 2020 | The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffe... |
| CVE-2020-3634 | CRITICAL | 9.1 | 1.1% | Sep 9, 2020 | u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdrago... |
| CVE-2020-3675 | CRITICAL | 9.8 | 1.1% | Sep 8, 2020 | u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' ... |
| CVE-2020-3669 | CRITICAL | 9.8 | 1.1% | Sep 8, 2020 | u'Buffer Overflow issue in WLAN tcp ip verification due to usage of out of range pointer offset' in Snapdragon Auto, Sna... |
| CVE-2020-3668 | CRITICAL | 9.8 | 1.1% | Sep 8, 2020 | u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while par... |
| CVE-2020-3667 | CRITICAL | 9.8 | 1.1% | Sep 8, 2020 | u'Buffer Overflow in mic calculation for WPA due to copying data into buffer without validating the length of buffer' in... |
| CVE-2020-11117 | CRITICAL | 9.8 | 20.1% | Sep 8, 2020 | u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arb... |
| CVE-2020-11116 | CRITICAL | 9.8 | 0.9% | Sep 8, 2020 | u'Possible out of bound write while processing association response received from host due to lack of check of IE length... |
| CVE-2020-24987 | CRITICAL | 9.8 | 3.1% | Sep 4, 2020 | Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution ... |
| CVE-2020-7730 | CRITICAL | 9.8 | 3.1% | Sep 4, 2020 | The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param. |
| CVE-2020-25023 | CRITICAL | 9.8 | 2.6% | Sep 4, 2020 | An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds ac... |
| CVE-2020-25022 | CRITICAL | 9.8 | 2.6% | Sep 4, 2020 | An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds... |
| CVE-2020-25021 | CRITICAL | 9.8 | 2.6% | Sep 4, 2020 | An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds acc... |
| CVE-2020-1911 | CRITICAL | 9.8 | 2.0% | Sep 4, 2020 | A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains i... |
| CVE-2020-24978 | CRITICAL | 9.8 | 1.4% | Sep 4, 2020 | In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca00... |
| CVE-2020-25006 | CRITICAL | 9.8 | 2.3% | Sep 3, 2020 | Heybbs v1.2 has a SQL injection vulnerability in login.php file via the username parameter which may allow a remote atta... |
| CVE-2020-25005 | CRITICAL | 9.8 | 2.3% | Sep 3, 2020 | Heybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to ... |
| CVE-2020-25004 | CRITICAL | 9.8 | 2.3% | Sep 3, 2020 | Heybbs v1.2 has a SQL injection vulnerability in user.php file via the ID parameter which may allow a remote attacker to... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now