2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11701 | HIGH | 8.8 | 0.5% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonst... |
| CVE-2020-11694 | HIGH | 7.5 | 1.8% | Apr 10, 2020 | In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed... |
| CVE-2020-11647 | HIGH | 7.5 | 3.3% | Apr 10, 2020 | In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed i... |
| CVE-2020-9056 | MEDIUM | 5.4 | 0.6% | Apr 10, 2020 | Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated a... |
| CVE-2020-6765 | HIGH | 7.2 | 1.2% | Apr 10, 2020 | D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a suppo... |
| CVE-2020-5406 | MEDIUM | 6.5 | 1.0% | Apr 10, 2020 | VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x vers... |
| CVE-2020-5330 | HIGH | 7.5 | 12.9% | Apr 10, 2020 | Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 ... |
| CVE-2020-5303 | LOW | 3.7 | 1.3% | Apr 10, 2020 | Tendermint before versions 0.33.3, 0.32.10, and 0.31.12 has a denial-of-service vulnerability. Tendermint does not limit... |
| CVE-2020-11002 | HIGH | 8.8 | 5.2% | Apr 10, 2020 | dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template... |
| CVE-2020-1801 | MEDIUM | 5.5 | 0.6% | Apr 10, 2020 | There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does ... |
| CVE-2020-11669 | MEDIUM | 5.5 | 0.5% | Apr 10, 2020 | An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does n... |
| CVE-2020-4362 | HIGH | 8.8 | 2.4% | Apr 10, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerabilit... |
| CVE-2020-3952 | CRITICAL | 9.8 | 90.4% | Apr 10, 2020 | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi... |
| CVE-2020-1802 | MEDIUM | 4.6 | 0.1% | Apr 10, 2020 | There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently valida... |
| CVE-2020-8832 | MEDIUM | 5.5 | 0.5% | Apr 10, 2020 | The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data struc... |
| CVE-2020-1633 | MEDIUM | 6.5 | 0.5% | Apr 9, 2020 | Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Ju... |
| CVE-2020-8834 | MEDIUM | 6.5 | 0.3% | Apr 9, 2020 | KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entr... |
| CVE-2020-11668 | HIGH | 7.1 | 0.5% | Apr 9, 2020 | In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles i... |
| CVE-2020-8961 | CRITICAL | 9.8 | 2.0% | Apr 9, 2020 | An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a w... |
| CVE-2020-7922 | MEDIUM | 6.5 | 0.7% | Apr 9, 2020 | X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kube... |
| CVE-2020-1895 | HIGH | 7.8 | 0.9% | Apr 9, 2020 | A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dim... |
| CVE-2020-5263 | MEDIUM | 4.9 | 0.9% | Apr 9, 2020 | auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of... |
| CVE-2020-9500 | MEDIUM | 4.9 | 1.0% | Apr 9, 2020 | Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the atta... |
| CVE-2020-9499 | HIGH | 7.2 | 1.5% | Apr 9, 2020 | Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker ... |
| CVE-2020-10631 | CRITICAL | 9.8 | 1.5% | Apr 9, 2020 | An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now