2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17463 | CRITICAL | 9.8 | 90.0% | Aug 13, 2020 | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. |
| CVE-2020-4589 | CRITICAL | 9.8 | 8.5% | Aug 13, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the s... |
| CVE-2020-16137 | CRITICAL | 9.8 | 19.4% | Aug 12, 2020 | A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to re... |
| CVE-2020-8904 | CRITICAL | 9.6 | 0.2% | Aug 12, 2020 | An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the eca... |
| CVE-2020-12107 | CRITICAL | 9.8 | 2.1% | Aug 12, 2020 | The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full cont... |
| CVE-2020-12106 | CRITICAL | 9.8 | 1.4% | Aug 12, 2020 | The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to severa... |
| CVE-2020-5415 | CRITICAL | 10 | 1.2% | Aug 12, 2020 | Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to ide... |
| CVE-2020-17506 | CRITICAL | 9.8 | 94.0% | Aug 12, 2020 | Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p... |
| CVE-2020-17446 | CRITICAL | 9.8 | 2.4% | Aug 12, 2020 | asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database c... |
| CVE-2020-6294 | CRITICAL | 9.1 | 1.5% | Aug 12, 2020 | Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any ... |
| CVE-2020-6284 | CRITICAL | 9 | 1.8% | Aug 12, 2020 | SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script conten... |
| CVE-2020-17496 | CRITICAL | 9.8 | 87.7% | Aug 12, 2020 | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe... |
| CVE-2020-6932 | CRITICAL | 9.8 | 3.6% | Aug 12, 2020 | An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Softwa... |
| CVE-2020-0260 | CRITICAL | 9.1 | 0.5% | Aug 11, 2020 | There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID:... |
| CVE-2020-0253 | CRITICAL | 9.8 | 0.6% | Aug 11, 2020 | There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-1526473... |
| CVE-2020-0252 | CRITICAL | 9.8 | 0.6% | Aug 11, 2020 | There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-1522368... |
| CVE-2020-17466 | CRITICAL | 9.8 | 1.5% | Aug 11, 2020 | Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redir... |
| CVE-2020-17368 | CRITICAL | 9.8 | 4.1% | Aug 11, 2020 | Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may ... |
| CVE-2020-11552 | CRITICAL | 9.8 | 7.4% | Aug 11, 2020 | An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not ... |
| CVE-2020-14324 | CRITICAL | 9.1 | 2.5% | Aug 11, 2020 | A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS... |
| CVE-2020-14325 | CRITICAL | 9.1 | 1.1% | Aug 11, 2020 | Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious at... |
| CVE-2020-17479 | CRITICAL | 9.8 | 2.5% | Aug 10, 2020 | jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array. |
| CVE-2020-9529 | CRITICAL | 9.8 | 2.9% | Aug 10, 2020 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions ... |
| CVE-2020-9527 | CRITICAL | 9.8 | 2.9% | Aug 10, 2020 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many... |
| CVE-2020-13292 | CRITICAL | 9.6 | 1.0% | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Fl... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now