2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12857 | HIGH | 7.5 | 1.6% | May 18, 2020 | Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re... |
| CVE-2020-12856 | CRITICAL | 9.8 | 5.1% | May 18, 2020 | OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Andro... |
| CVE-2020-13128 | HIGH | 7.5 | 1.6% | May 18, 2020 | An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) acce... |
| CVE-2020-4345 | LOW | 3.3 | 0.3% | May 17, 2020 | IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local use... |
| CVE-2020-13126 | CRITICAL | 9.9 | 8.6% | May 17, 2020 | An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in ... |
| CVE-2020-13125 | MEDIUM | 6.5 | 2.3% | May 17, 2020 | An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the w... |
| CVE-2020-13121 | MEDIUM | 6.1 | 3.5% | May 16, 2020 | Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt. |
| CVE-2020-13118 | CRITICAL | 9.8 | 4.0% | May 16, 2020 | An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community... |
| CVE-2020-13111 | HIGH | 7.5 | 1.4% | May 16, 2020 | NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly valida... |
| CVE-2020-13110 | HIGH | 7.8 | 0.7% | May 16, 2020 | The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of ... |
| CVE-2020-13109 | CRITICAL | 9.8 | 4.8% | May 16, 2020 | Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted... |
| CVE-2020-8149 | CRITICAL | 9.8 | 2.0% | May 15, 2020 | Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before ve... |
| CVE-2020-1758 | MEDIUM | 5.9 | 0.9% | May 15, 2020 | A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while se... |
| CVE-2020-13093 | MEDIUM | 5.3 | 1.3% | May 15, 2020 | iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal. |
| CVE-2020-13092 | CRITICAL | 9.8 | 2.6% | May 15, 2020 | scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to ... |
| CVE-2020-13091 | CRITICAL | 9.8 | 3.4% | May 15, 2020 | pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() fun... |
| CVE-2020-12872 | MEDIUM | 5.5 | 0.4% | May 15, 2020 | yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet3... |
| CVE-2020-12889 | CRITICAL | 9.8 | 1.2% | May 15, 2020 | MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case. |
| CVE-2020-12888 | MEDIUM | 5.3 | 0.4% | May 15, 2020 | The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. |
| CVE-2020-12798 | HIGH | 7.8 | 0.3% | May 15, 2020 | Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command... |
| CVE-2020-12651 | CRITICAL | 9.8 | 6.6% | May 15, 2020 | SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow b... |
| CVE-2020-12834 | CRITICAL | 9.8 | 11.1% | May 15, 2020 | eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSO... |
| CVE-2020-12685 | MEDIUM | 6.1 | 0.8% | May 15, 2020 | XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote... |
| CVE-2020-11526 | LOW | 2.2 | 2.0% | May 15, 2020 | libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read. |
| CVE-2020-11525 | LOW | 2.2 | 1.7% | May 15, 2020 | libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now