2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14524 | CRITICAL | 9.8 | 2.5% | Aug 25, 2020 | Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerab... |
| CVE-2020-14510 | CRITICAL | 9.8 | 2.5% | Aug 25, 2020 | GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unpriv... |
| CVE-2020-14508 | CRITICAL | 9.8 | 2.0% | Aug 25, 2020 | GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attack... |
| CVE-2020-14500 | CRITICAL | 9.8 | 1.7% | Aug 25, 2020 | Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data. |
| CVE-2020-7376 | CRITICAL | 9.8 | 1.1% | Aug 24, 2020 | The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability... |
| CVE-2020-6637 | CRITICAL | 9.8 | 20.1% | Aug 24, 2020 | openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php. |
| CVE-2020-24186 | CRITICAL | 10 | 94.6% | Aug 24, 2020 | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo... |
| CVE-2020-8234 | CRITICAL | 9.8 | 3.4% | Aug 21, 2020 | A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cooki... |
| CVE-2020-24590 | CRITICAL | 9.1 | 1.3% | Aug 21, 2020 | The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks. |
| CVE-2020-24589 | CRITICAL | 9.1 | 26.9% | Aug 21, 2020 | The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection... |
| CVE-2020-15140 | CRITICAL | 9.6 | 0.9% | Aug 21, 2020 | In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Di... |
| CVE-2020-24055 | CRITICAL | 9.8 | 1.6% | Aug 21, 2020 | Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service im... |
| CVE-2020-24054 | CRITICAL | 9.8 | 2.6% | Aug 21, 2020 | The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that... |
| CVE-2020-24052 | CRITICAL | 9.1 | 1.9% | Aug 21, 2020 | Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unaut... |
| CVE-2020-24051 | CRITICAL | 9.8 | 2.2% | Aug 21, 2020 | The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol,... |
| CVE-2020-7710 | CRITICAL | 9.8 | 1.4% | Aug 21, 2020 | This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host m... |
| CVE-2020-16279 | CRITICAL | 9.8 | 2.3% | Aug 20, 2020 | The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplie... |
| CVE-2020-23935 | CRITICAL | 9.8 | 15.9% | Aug 20, 2020 | Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (... |
| CVE-2020-23936 | CRITICAL | 9.8 | 1.4% | Aug 20, 2020 | PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Passwo... |
| CVE-2020-10283 | CRITICAL | 9.8 | 1.5% | Aug 20, 2020 | The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to... |
| CVE-2020-17456 | CRITICAL | 9.8 | 70.9% | Aug 20, 2020 | SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa... |
| CVE-2020-15636 | CRITICAL | 9.8 | 8.5% | Aug 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, ... |
| CVE-2020-15149 | CRITICAL | 9.9 | 2.4% | Aug 20, 2020 | NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to ch... |
| CVE-2020-24032 | CRITICAL | 9.8 | 5.4% | Aug 18, 2020 | tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharac... |
| CVE-2020-15865 | CRITICAL | 9.8 | 5.1% | Aug 18, 2020 | A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now