2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11102 | MEDIUM | 5.6 | 1.9% | Apr 6, 2020 | hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not val... |
| CVE-2020-9473 | MEDIUM | 6.6 | 1.0% | Apr 6, 2020 | The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, a... |
| CVE-2020-7622 | CRITICAL | 9.8 | 1.6% | Apr 6, 2020 | This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set t... |
| CVE-2020-1728 | MEDIUM | 5.4 | 0.8% | Apr 6, 2020 | A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are ... |
| CVE-2020-8004 | HIGH | 7.5 | 3.0% | Apr 6, 2020 | STMicroelectronics STM32F1 devices have Incorrect Access Control. |
| CVE-2020-7639 | MEDIUM | 5.3 | 1.1% | Apr 6, 2020 | eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or ... |
| CVE-2020-7638 | MEDIUM | 5.3 | 1.0% | Apr 6, 2020 | confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding ... |
| CVE-2020-7637 | MEDIUM | 5.3 | 1.2% | Apr 6, 2020 | class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could ... |
| CVE-2020-7636 | CRITICAL | 9.8 | 4.4% | Apr 6, 2020 | adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command fu... |
| CVE-2020-7635 | CRITICAL | 9.8 | 4.4% | Apr 6, 2020 | compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha optio... |
| CVE-2020-7634 | CRITICAL | 9.8 | 2.8% | Apr 6, 2020 | heroku-addonpool through 0.1.15 is vulnerable to Command Injection. |
| CVE-2020-7633 | CRITICAL | 9.8 | 4.4% | Apr 6, 2020 | apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via th... |
| CVE-2020-7632 | CRITICAL | 9.8 | 4.4% | Apr 6, 2020 | node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options arg... |
| CVE-2020-7631 | CRITICAL | 9.8 | 3.9% | Apr 6, 2020 | diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path arg... |
| CVE-2020-10267 | HIGH | 7.5 | 0.9% | Apr 6, 2020 | Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or... |
| CVE-2020-10266 | HIGH | 8.1 | 0.5% | Apr 6, 2020 | UR+ (Universal Robots+) is a platform of hardware and software component sellers, for Universal Robots robots. When inst... |
| CVE-2020-10265 | CRITICAL | 9.4 | 1.4% | Apr 6, 2020 | Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Versi... |
| CVE-2020-10264 | HIGH | 8.8 | 0.6% | Apr 6, 2020 | CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Da... |
| CVE-2020-11565 | MEDIUM | 6 | 0.5% | Apr 6, 2020 | An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bou... |
| CVE-2020-11558 | CRITICAL | 9.8 | 1.5% | Apr 5, 2020 | An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_c... |
| CVE-2020-11548 | CRITICAL | 9.8 | 5.2% | Apr 5, 2020 | The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. T... |
| CVE-2020-11547 | MEDIUM | 5.3 | 52.1% | Apr 5, 2020 | PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes runn... |
| CVE-2020-11542 | CRITICAL | 9.8 | 1.0% | Apr 4, 2020 | 3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication... |
| CVE-2020-11533 | MEDIUM | 5.5 | 0.5% | Apr 4, 2020 | Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive info... |
| CVE-2020-11529 | MEDIUM | 6.1 | 10.9% | Apr 4, 2020 | Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now