2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12835 | CRITICAL | 9.8 | 11.7% | May 20, 2020 | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an un... |
| CVE-2020-13226 | CRITICAL | 9.8 | 2.1% | May 20, 2020 | WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibil... |
| CVE-2020-5579 | HIGH | 7.2 | 1.2% | May 20, 2020 | SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to... |
| CVE-2020-13225 | MEDIUM | 4.8 | 0.6% | May 20, 2020 | phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the Us... |
| CVE-2020-9753 | CRITICAL | 9.1 | 1.1% | May 20, 2020 | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. |
| CVE-2020-12034 | HIGH | 8.2 | 1.3% | May 20, 2020 | Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterpris... |
| CVE-2020-7139 | HIGH | 8.1 | 0.9% | May 19, 2020 | Potential remote access security vulnerabilities have been identified with HPE Nimble Storage systems that could be expl... |
| CVE-2020-7138 | HIGH | 8.8 | 1.8% | May 19, 2020 | Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could... |
| CVE-2020-7137 | MEDIUM | 6.7 | 0.3% | May 19, 2020 | A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Fle... |
| CVE-2020-13164 | HIGH | 7.5 | 3.2% | May 19, 2020 | In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in ... |
| CVE-2020-13163 | HIGH | 7.4 | 0.8% | May 19, 2020 | em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle atta... |
| CVE-2020-12038 | MEDIUM | 5.5 | 2.5% | May 19, 2020 | Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterpris... |
| CVE-2020-7656 | MEDIUM | 6.1 | 6.3% | May 19, 2020 | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re... |
| CVE-2020-2025 | HIGH | 8.8 | 0.3% | May 19, 2020 | Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the ... |
| CVE-2020-2024 | MEDIUM | 6.5 | 0.4% | May 19, 2020 | An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a m... |
| CVE-2020-13167 | CRITICAL | 9.8 | 95.4% | May 19, 2020 | Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain... |
| CVE-2020-13166 | CRITICAL | 9.8 | 77.6% | May 19, 2020 | The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod... |
| CVE-2020-11766 | HIGH | 8.8 | 1.8% | May 19, 2020 | sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command... |
| CVE-2020-10724 | MEDIUM | 4.4 | 0.4% | May 19, 2020 | A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for use... |
| CVE-2020-10723 | MEDIUM | 6.7 | 0.4% | May 19, 2020 | A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on th... |
| CVE-2020-10722 | MEDIUM | 6.7 | 0.4% | May 19, 2020 | A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_lo... |
| CVE-2020-11715 | CRITICAL | 9.8 | 1.4% | May 19, 2020 | Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected produc... |
| CVE-2020-10995 | HIGH | 7.5 | 4.4% | May 19, 2020 | PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An is... |
| CVE-2020-11807 | HIGH | 7.8 | 0.7% | May 19, 2020 | Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user... |
| CVE-2020-10135 | MEDIUM | 5.4 | 2.4% | May 19, 2020 | Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now