2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19229 | CRITICAL | 9.8 | 1.4% | Apr 5, 2022 | Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deseria... |
| CVE-2020-28062 | HIGH | 7.2 | 2.4% | Apr 4, 2022 | An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getLi... |
| CVE-2020-25691 | HIGH | 7.5 | 1.3% | Apr 1, 2022 | A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a ... |
| CVE-2020-14479 | MEDIUM | 5.3 | 0.9% | Apr 1, 2022 | Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper... |
| CVE-2020-35501 | LOW | 3.4 | 0.2% | Mar 30, 2022 | A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly n... |
| CVE-2020-24771 | HIGH | 7.5 | 2.0% | Mar 30, 2022 | Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content. |
| CVE-2020-24770 | CRITICAL | 9.8 | 2.4% | Mar 30, 2022 | SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2020-24769 | CRITICAL | 9.8 | 1.9% | Mar 30, 2022 | SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands... |
| CVE-2020-21554 | HIGH | 8.1 | 1.5% | Mar 25, 2022 | A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could ... |
| CVE-2020-20096 | MEDIUM | 6.5 | 1.4% | Mar 23, 2022 | Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to... |
| CVE-2020-20095 | MEDIUM | 6.5 | 1.3% | Mar 23, 2022 | iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which re... |
| CVE-2020-20094 | MEDIUM | 6.5 | 1.4% | Mar 23, 2022 | Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages t... |
| CVE-2020-20093 | MEDIUM | 6.5 | 2.3% | Mar 23, 2022 | The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly... |
| CVE-2020-24772 | HIGH | 8.8 | 0.6% | Mar 21, 2022 | In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that ... |
| CVE-2020-26008 | HIGH | 7.8 | 0.9% | Mar 20, 2022 | The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file up... |
| CVE-2020-26007 | HIGH | 7.8 | 0.9% | Mar 20, 2022 | An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitra... |
| CVE-2020-25197 | HIGH | 8.8 | 3.0% | Mar 18, 2022 | A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware v... |
| CVE-2020-25193 | MEDIUM | 5.3 | 0.8% | Mar 18, 2022 | By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions... |
| CVE-2020-25184 | MEDIUM | 5.5 | 0.4% | Mar 18, 2022 | Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same ... |
| CVE-2020-25182 | MEDIUM | 6.7 | 0.4% | Mar 18, 2022 | Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled ... |
| CVE-2020-25180 | MEDIUM | 6.5 | 1.1% | Mar 18, 2022 | Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is requir... |
| CVE-2020-25178 | HIGH | 8.8 | 1.6% | Mar 18, 2022 | ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communic... |
| CVE-2020-25176 | CRITICAL | 9.8 | 6.1% | Mar 18, 2022 | Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform... |
| CVE-2020-16232 | CRITICAL | 9.8 | 0.7% | Mar 18, 2022 | In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project ... |
| CVE-2020-15388 | MEDIUM | 6.5 | 0.7% | Mar 18, 2022 | A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now