2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1891 | CRITICAL | 9.8 | 1.5% | Sep 3, 2020 | A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android ... |
| CVE-2020-1889 | CRITICAL | 10 | 4.8% | Sep 3, 2020 | A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in... |
| CVE-2020-24193 | CRITICAL | 9.8 | 2.8% | Sep 3, 2020 | A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execu... |
| CVE-2020-24876 | CRITICAL | 9.8 | 1.7% | Sep 3, 2020 | Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which m... |
| CVE-2020-25105 | CRITICAL | 9.8 | 1.1% | Sep 3, 2020 | eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilit... |
| CVE-2020-4693 | CRITICAL | 9.8 | 2.5% | Sep 2, 2020 | IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to exe... |
| CVE-2020-24030 | CRITICAL | 9.8 | 2.7% | Sep 2, 2020 | ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access... |
| CVE-2020-24029 | CRITICAL | 9.8 | 2.0% | Sep 2, 2020 | Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can b... |
| CVE-2020-13802 | CRITICAL | 9.8 | 6.8% | Sep 2, 2020 | Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specificat... |
| CVE-2020-24355 | CRITICAL | 9.8 | 2.2% | Sep 2, 2020 | Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insec... |
| CVE-2020-6874 | CRITICAL | 9.1 | 0.4% | Sep 1, 2020 | A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so r... |
| CVE-2020-6151 | CRITICAL | 9.8 | 1.6% | Sep 1, 2020 | A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19.... |
| CVE-2020-6144 | CRITICAL | 9.8 | 6.3% | Sep 1, 2020 | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable wh... |
| CVE-2020-6143 | CRITICAL | 9.8 | 6.2% | Sep 1, 2020 | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable wh... |
| CVE-2020-6142 | CRITICAL | 9.8 | 9.2% | Sep 1, 2020 | A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. A specially crafted ... |
| CVE-2020-6140 | CRITICAL | 9.8 | 2.6% | Sep 1, 2020 | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email para... |
| CVE-2020-6139 | CRITICAL | 9.8 | 2.6% | Sep 1, 2020 | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The username_stf_email para... |
| CVE-2020-6138 | CRITICAL | 9.8 | 2.6% | Sep 1, 2020 | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The uname parameter in the ... |
| CVE-2020-6137 | CRITICAL | 9.8 | 2.6% | Sep 1, 2020 | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email para... |
| CVE-2020-5777 | CRITICAL | 9.8 | 23.9% | Sep 1, 2020 | MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in t... |
| CVE-2020-25069 | CRITICAL | 9.8 | 1.9% | Sep 1, 2020 | USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view. |
| CVE-2020-16210 | CRITICAL | 9 | 3.2% | Sep 1, 2020 | The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute ar... |
| CVE-2020-16206 | CRITICAL | 9 | 3.2% | Sep 1, 2020 | The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbit... |
| CVE-2020-16204 | CRITICAL | 9.8 | 5.5% | Sep 1, 2020 | The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to ... |
| CVE-2020-6141 | CRITICAL | 9.8 | 3.9% | Sep 1, 2020 | An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted H... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now