2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10629 | HIGH | 7.5 | 1.2% | Apr 9, 2020 | WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker... |
| CVE-2020-10625 | CRITICAL | 9.8 | 1.6% | Apr 9, 2020 | WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account. |
| CVE-2020-10623 | MEDIUM | 6.5 | 0.9% | Apr 9, 2020 | Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions... |
| CVE-2020-10619 | CRITICAL | 9.1 | 14.3% | Apr 9, 2020 | An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) cont... |
| CVE-2020-10617 | HIGH | 7.5 | 1.3% | Apr 9, 2020 | There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0.... |
| CVE-2020-10603 | HIGH | 8.8 | 1.2% | Apr 9, 2020 | WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system... |
| CVE-2020-11557 | HIGH | 7.5 | 0.7% | Apr 9, 2020 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password va... |
| CVE-2020-11556 | MEDIUM | 5.4 | 0.6% | Apr 9, 2020 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) a... |
| CVE-2020-11555 | HIGH | 7.5 | 1.4% | Apr 9, 2020 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sen... |
| CVE-2020-11554 | HIGH | 7.5 | 1.5% | Apr 9, 2020 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sen... |
| CVE-2020-11553 | HIGH | 8.8 | 0.5% | Apr 9, 2020 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF. |
| CVE-2020-10621 | CRITICAL | 9.8 | 1.6% | Apr 9, 2020 | Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2). |
| CVE-2020-10551 | HIGH | 7.8 | 1.4% | Apr 9, 2020 | QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to th... |
| CVE-2020-11656 | CRITICAL | 9.8 | 7.4% | Apr 9, 2020 | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause tha... |
| CVE-2020-11655 | HIGH | 7.5 | 5.1% | Apr 9, 2020 | SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function... |
| CVE-2020-11653 | HIGH | 7.5 | 2.1% | Apr 8, 2020 | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occu... |
| CVE-2020-11650 | HIGH | 7.5 | 3.0% | Apr 8, 2020 | An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a deni... |
| CVE-2020-2732 | MEDIUM | 6.8 | 0.9% | Apr 8, 2020 | A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtu... |
| CVE-2020-8828 | HIGH | 8.8 | 1.8% | Apr 8, 2020 | As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster o... |
| CVE-2020-8827 | HIGH | 7.5 | 2.2% | Apr 8, 2020 | As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other... |
| CVE-2020-8826 | HIGH | 7.5 | 1.7% | Apr 8, 2020 | As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, ... |
| CVE-2020-1885 | HIGH | 7.8 | 0.4% | Apr 8, 2020 | Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows ... |
| CVE-2020-1639 | HIGH | 7.5 | 1.1% | Apr 8, 2020 | When an attacker sends a specific crafted Ethernet Operation, Administration, and Maintenance (Ethernet OAM) packet to a... |
| CVE-2020-1638 | HIGH | 7.5 | 1.3% | Apr 8, 2020 | The FPC (Flexible PIC Concentrator) of Juniper Networks Junos OS and Junos OS Evolved may restart after processing a spe... |
| CVE-2020-1637 | MEDIUM | 6.5 | 0.8% | Apr 8, 2020 | A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to acces... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now