2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16169 | CRITICAL | 9.8 | 2.4% | Aug 7, 2020 | Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 a... |
| CVE-2020-16167 | CRITICAL | 9.1 | 2.1% | Aug 7, 2020 | Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remot... |
| CVE-2020-13376 | CRITICAL | 9 | 3.5% | Aug 7, 2020 | SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted ... |
| CVE-2020-11984 | CRITICAL | 9.8 | 90.0% | Aug 7, 2020 | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
| CVE-2020-8025 | CRITICAL | 9.3 | 0.5% | Aug 7, 2020 | A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-S... |
| CVE-2020-13793 | CRITICAL | 9.8 | 1.7% | Aug 6, 2020 | Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key. |
| CVE-2020-12441 | CRITICAL | 9.8 | 3.8% | Aug 6, 2020 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parse... |
| CVE-2020-7357 | CRITICAL | 9.9 | 33.9% | Aug 6, 2020 | Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This ca... |
| CVE-2020-7356 | CRITICAL | 9.8 | 14.0% | Aug 6, 2020 | CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_s... |
| CVE-2020-5609 | CRITICAL | 9.8 | 2.1% | Aug 5, 2020 | Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, C... |
| CVE-2020-5608 | CRITICAL | 9.8 | 1.6% | Aug 5, 2020 | CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, B... |
| CVE-2020-17353 | CRITICAL | 9.8 | 2.4% | Aug 5, 2020 | scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restri... |
| CVE-2020-13921 | CRITICAL | 9.8 | 33.5% | Aug 5, 2020 | **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the w... |
| CVE-2020-13151 | CRITICAL | 9.8 | 86.7% | Aug 5, 2020 | Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)... |
| CVE-2020-4459 | CRITICAL | 9.8 | 1.0% | Aug 4, 2020 | IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses ... |
| CVE-2020-5616 | CRITICAL | 9.8 | 3.1% | Aug 4, 2020 | [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Cale... |
| CVE-2020-16272 | CRITICAL | 9.1 | 2.8% | Aug 3, 2020 | The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, w... |
| CVE-2020-16271 | CRITICAL | 9.1 | 1.5% | Aug 3, 2020 | The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows re... |
| CVE-2020-4377 | CRITICAL | 9.1 | 2.1% | Aug 3, 2020 | IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML dat... |
| CVE-2020-5413 | CRITICAL | 9.8 | 4.4% | Jul 31, 2020 | Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo... |
| CVE-2020-10731 | CRITICAL | 9.9 | 0.9% | Jul 31, 2020 | A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SEL... |
| CVE-2020-3681 | CRITICAL | 9.8 | 0.7% | Jul 31, 2020 | Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recov... |
| CVE-2020-3382 | CRITICAL | 9.8 | 2.3% | Jul 31, 2020 | A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attac... |
| CVE-2020-3376 | CRITICAL | 9.8 | 1.2% | Jul 31, 2020 | A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthentic... |
| CVE-2020-3375 | CRITICAL | 9.8 | 3.9% | Jul 31, 2020 | A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer over... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now