2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6458 | HIGH | 8.8 | 1.3% | May 21, 2020 | Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially ... |
| CVE-2020-6457 | CRITICAL | 9.6 | 1.2% | May 21, 2020 | Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially per... |
| CVE-2020-13252 | HIGH | 8.8 | 5.4% | May 21, 2020 | Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRD... |
| CVE-2020-12647 | HIGH | 8.8 | 0.4% | May 21, 2020 | Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences... |
| CVE-2020-5365 | HIGH | 7.5 | 1.0% | May 20, 2020 | Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, re... |
| CVE-2020-5364 | HIGH | 7.5 | 1.0% | May 20, 2020 | Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by def... |
| CVE-2020-9484 | HIGH | 7 | 56.6% | May 20, 2020 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a)... |
| CVE-2020-13249 | HIGH | 8.8 | 2.2% | May 20, 2020 | libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet rece... |
| CVE-2020-13241 | HIGH | 7.8 | 0.5% | May 20, 2020 | Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not veri... |
| CVE-2020-13246 | HIGH | 7.5 | 2.0% | May 20, 2020 | An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a reposi... |
| CVE-2020-11078 | MEDIUM | 6.8 | 2.6% | May 20, 2020 | In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could cha... |
| CVE-2020-13240 | MEDIUM | 5.4 | 0.7% | May 20, 2020 | The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded ... |
| CVE-2020-13239 | MEDIUM | 5.4 | 0.7% | May 20, 2020 | The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is ... |
| CVE-2020-5753 | MEDIUM | 5.3 | 1.1% | May 20, 2020 | Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's S... |
| CVE-2020-3956 | HIGH | 8.8 | 21.1% | May 20, 2020 | VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4... |
| CVE-2020-1955 | CRITICAL | 9.8 | 1.8% | May 20, 2020 | CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server... |
| CVE-2020-13231 | MEDIUM | 6.5 | 0.8% | May 20, 2020 | In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change. |
| CVE-2020-13230 | MEDIUM | 4.3 | 1.0% | May 20, 2020 | In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account... |
| CVE-2020-11716 | CRITICAL | 9.8 | 1.4% | May 20, 2020 | Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the... |
| CVE-2020-10726 | MEDIUM | 4.4 | 0.5% | May 20, 2020 | A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-us... |
| CVE-2020-10725 | HIGH | 7.7 | 2.2% | May 20, 2020 | A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhos... |
| CVE-2020-9410 | HIGH | 8.8 | 5.1% | May 20, 2020 | The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for Act... |
| CVE-2020-9409 | CRITICAL | 9.8 | 3.4% | May 20, 2020 | The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS ... |
| CVE-2020-4461 | MEDIUM | 6.5 | 0.9% | May 20, 2020 | IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token ... |
| CVE-2020-13152 | MEDIUM | 5.5 | 3.4% | May 20, 2020 | A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will tri... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now