2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11528 | HIGH | 7.5 | 1.2% | Apr 4, 2020 | bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a b... |
| CVE-2020-11527 | HIGH | 7.5 | 9.5% | Apr 4, 2020 | In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to r... |
| CVE-2020-11518 | CRITICAL | 9.8 | 18.8% | Apr 4, 2020 | Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution. |
| CVE-2020-5348 | HIGH | 7.8 | 0.4% | Apr 4, 2020 | Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system m... |
| CVE-2020-5347 | HIGH | 7.5 | 1.0% | Apr 4, 2020 | Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error co... |
| CVE-2020-8147 | CRITICAL | 9.8 | 3.1% | Apr 3, 2020 | Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that... |
| CVE-2020-8143 | MEDIUM | 6.1 | 70.4% | Apr 3, 2020 | An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn14... |
| CVE-2020-8142 | MEDIUM | 6.8 | 0.6% | Apr 3, 2020 | A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoa... |
| CVE-2020-8639 | HIGH | 8.8 | 15.9% | Apr 3, 2020 | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute ar... |
| CVE-2020-8638 | CRITICAL | 9.8 | 1.7% | Apr 3, 2020 | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php v... |
| CVE-2020-8637 | CRITICAL | 9.8 | 2.9% | Apr 3, 2020 | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes... |
| CVE-2020-6994 | CRITICAL | 9.8 | 1.6% | Apr 3, 2020 | A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vul... |
| CVE-2020-7008 | HIGH | 7.5 | 1.9% | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly v... |
| CVE-2020-7004 | HIGH | 8.8 | 0.4% | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE dire... |
| CVE-2020-7000 | HIGH | 7.5 | 1.1% | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cr... |
| CVE-2020-10601 | HIGH | 7.8 | 0.2% | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions wh... |
| CVE-2020-10599 | CRITICAL | 9.8 | 2.5% | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited... |
| CVE-2020-10960 | MEDIUM | 5.3 | 1.1% | Apr 3, 2020 | In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is... |
| CVE-2020-10689 | MEDIUM | 6.8 | 0.8% | Apr 3, 2020 | A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An... |
| CVE-2020-4273 | HIGH | 7.8 | 0.4% | Apr 3, 2020 | IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to e... |
| CVE-2020-11501 | HIGH | 7.4 | 3.4% | Apr 3, 2020 | GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) bec... |
| CVE-2020-11500 | HIGH | 7.5 | 1.3% | Apr 3, 2020 | Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all pa... |
| CVE-2020-5283 | LOW | 3.5 | 1.2% | Apr 3, 2020 | ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this v... |
| CVE-2020-11499 | MEDIUM | 6.1 | 0.6% | Apr 2, 2020 | Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request... |
| CVE-2020-11498 | HIGH | 8.8 | 3.4% | Apr 2, 2020 | Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now