2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12242 | HIGH | 7.8 | 1.1% | Apr 27, 2020 | Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in ... |
| CVE-2020-12138 | HIGH | 8.8 | 3.3% | Apr 27, 2020 | AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of se... |
| CVE-2020-12133 | CRITICAL | 9.8 | 9.9% | Apr 27, 2020 | The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of... |
| CVE-2020-12120 | HIGH | 7.5 | 1.8% | Apr 27, 2020 | The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such a... |
| CVE-2020-11822 | MEDIUM | 6.1 | 0.8% | Apr 27, 2020 | In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus... |
| CVE-2020-11821 | MEDIUM | 5.3 | 1.1% | Apr 27, 2020 | In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hash... |
| CVE-2020-11817 | CRITICAL | 9.8 | 2.0% | Apr 27, 2020 | In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As... |
| CVE-2020-11810 | LOW | 3.7 | 1.6% | Apr 27, 2020 | An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using... |
| CVE-2020-11415 | MEDIUM | 4.9 | 0.6% | Apr 27, 2020 | An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can r... |
| CVE-2020-9489 | MEDIUM | 5.5 | 2.5% | Apr 27, 2020 | A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can a... |
| CVE-2020-12272 | MEDIUM | 5.3 | 2.1% | Apr 27, 2020 | OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about t... |
| CVE-2020-11420 | MEDIUM | 6.5 | 1.6% | Apr 27, 2020 | UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exp... |
| CVE-2020-12274 | CRITICAL | 9.8 | 1.2% | Apr 27, 2020 | In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on ... |
| CVE-2020-12273 | HIGH | 7.5 | 0.8% | Apr 27, 2020 | In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials. |
| CVE-2020-12052 | MEDIUM | 6.1 | 1.3% | Apr 27, 2020 | Grafana version < 6.7.3 is vulnerable for annotation popup XSS. |
| CVE-2020-10997 | MEDIUM | 6.5 | 1.0% | Apr 27, 2020 | Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may i... |
| CVE-2020-10996 | HIGH | 8.1 | 1.5% | Apr 27, 2020 | An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static tr... |
| CVE-2020-10664 | HIGH | 7.5 | 1.3% | Apr 27, 2020 | The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference. |
| CVE-2020-10647 | — | — | — | Apr 27, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-12271 | CRITICAL | 9.8 | 43.1% | Apr 27, 2020 | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as e... |
| CVE-2020-12270 | MEDIUM | 6.5 | 1.4% | Apr 27, 2020 | React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote... |
| CVE-2020-12268 | CRITICAL | 9.8 | 2.6% | Apr 27, 2020 | jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow. |
| CVE-2020-12267 | CRITICAL | 9.8 | 2.3% | Apr 27, 2020 | setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock. |
| CVE-2020-12265 | CRITICAL | 9.8 | 2.2% | Apr 26, 2020 | The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when... |
| CVE-2020-12254 | HIGH | 7.8 | 0.4% | Apr 26, 2020 | Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlin... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now