2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12642 | HIGH | 7.5 | 1.3% | May 4, 2020 | An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resulta... |
| CVE-2020-12109 | HIGH | 8.8 | 74.3% | May 4, 2020 | Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 ... |
| CVE-2020-12641 | CRITICAL | 9.8 | 84.5% | May 4, 2020 | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in... |
| CVE-2020-12640 | CRITICAL | 9.8 | 6.7% | May 4, 2020 | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plu... |
| CVE-2020-12111 | HIGH | 8.8 | 8.0% | May 4, 2020 | Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304. |
| CVE-2020-10933 | MEDIUM | 5.3 | 2.6% | May 4, 2020 | An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_... |
| CVE-2020-8792 | MEDIUM | 5.3 | 1.0% | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. I... |
| CVE-2020-8791 | MEDIUM | 6.5 | 1.0% | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit AP... |
| CVE-2020-8790 | CRITICAL | 9.8 | 1.7% | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combi... |
| CVE-2020-4209 | MEDIUM | 5.4 | 1.4% | May 4, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An ... |
| CVE-2020-12639 | MEDIUM | 6.1 | 0.7% | May 4, 2020 | phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php. |
| CVE-2020-12475 | MEDIUM | 5.5 | 0.6% | May 4, 2020 | TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.p... |
| CVE-2020-12110 | CRITICAL | 9.8 | 14.4% | May 4, 2020 | Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304,... |
| CVE-2020-11671 | HIGH | 8.1 | 1.1% | May 4, 2020 | Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid... |
| CVE-2020-11462 | HIGH | 7.5 | 1.3% | May 4, 2020 | An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interf... |
| CVE-2020-11443 | HIGH | 8.1 | 1.5% | May 4, 2020 | The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoo... |
| CVE-2020-10876 | HIGH | 7.5 | 1.1% | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its tim... |
| CVE-2020-10187 | HIGH | 7.5 | 2.0% | May 4, 2020 | Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve ... |
| CVE-2020-1961 | CRITICAL | 9.8 | 4.6% | May 4, 2020 | Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1... |
| CVE-2020-1959 | CRITICAL | 9.8 | 4.8% | May 4, 2020 | A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary ... |
| CVE-2020-12629 | MEDIUM | 5.4 | 1.5% | May 4, 2020 | include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. |
| CVE-2020-11842 | HIGH | 7.5 | 1.1% | May 4, 2020 | Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier... |
| CVE-2020-8018 | HIGH | 7.8 | 0.3% | May 4, 2020 | A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of ... |
| CVE-2020-12114 | MEDIUM | 4.7 | 0.4% | May 4, 2020 | A pivot_root race condition in fs/namespace.c in the Linux kernel 4.4.x before 4.4.221, 4.9.x before 4.9.221, 4.14.x bef... |
| CVE-2020-1631 | CRITICAL | 9.8 | 4.7% | May 4, 2020 | A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now