2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11416 | MEDIUM | 5.4 | 0.5% | Apr 22, 2020 | JetBrains Space through 2020-04-22 allows stored XSS in Chats. |
| CVE-2020-12059 | HIGH | 7.5 | 2.7% | Apr 22, 2020 | An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by ... |
| CVE-2020-12051 | HIGH | 7.5 | 1.3% | Apr 21, 2020 | The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account infor... |
| CVE-2020-5301 | LOW | 3.1 | 0.9% | Apr 21, 2020 | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSA... |
| CVE-2020-11008 | HIGH | 7.5 | 3.9% | Apr 21, 2020 | Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host cont... |
| CVE-2020-10569 | CRITICAL | 9.8 | 3.2% | Apr 21, 2020 | SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additiona... |
| CVE-2020-8895 | HIGH | 7.8 | 0.2% | Apr 21, 2020 | Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attac... |
| CVE-2020-5268 | HIGH | 7.3 | 1.1% | Apr 21, 2020 | In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerabilit... |
| CVE-2020-1757 | HIGH | 8.1 | 1.6% | Apr 21, 2020 | A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x ... |
| CVE-2020-1699 | HIGH | 7.5 | 2.1% | Apr 21, 2020 | A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph... |
| CVE-2020-11891 | MEDIUM | 5.3 | 0.8% | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow th... |
| CVE-2020-11890 | MEDIUM | 5.3 | 2.8% | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to ... |
| CVE-2020-11889 | MEDIUM | 5.3 | 0.8% | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow th... |
| CVE-2020-10787 | HIGH | 8.8 | 2.5% | Apr 21, 2020 | An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the... |
| CVE-2020-10786 | HIGH | 8.8 | 4.8% | Apr 21, 2020 | A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary co... |
| CVE-2020-8842 | — | — | — | Apr 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-1967 | HIGH | 7.5 | 53.3% | Apr 21, 2020 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due... |
| CVE-2020-11828 | HIGH | 7.5 | 1.2% | Apr 21, 2020 | In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger su... |
| CVE-2020-8099 | MEDIUM | 6.2 | 0.4% | Apr 21, 2020 | A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to su... |
| CVE-2020-11968 | HIGH | 7.5 | 2.6% | Apr 21, 2020 | In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. N... |
| CVE-2020-11967 | CRITICAL | 9.8 | 3.2% | Apr 21, 2020 | In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of ... |
| CVE-2020-11966 | CRITICAL | 9.8 | 3.0% | Apr 21, 2020 | In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root p... |
| CVE-2020-11965 | CRITICAL | 9.8 | 2.0% | Apr 21, 2020 | In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access vi... |
| CVE-2020-11964 | HIGH | 7.5 | 2.2% | Apr 21, 2020 | In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the roo... |
| CVE-2020-11963 | CRITICAL | 9.8 | 3.1% | Apr 21, 2020 | IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now