2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15715 | CRITICAL | 9.9 | 4.2% | Jul 28, 2020 | rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error i... |
| CVE-2020-16088 | CRITICAL | 9.8 | 2.4% | Jul 28, 2020 | iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for chec... |
| CVE-2020-12460 | CRITICAL | 9.8 | 3.7% | Jul 27, 2020 | OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse ... |
| CVE-2020-12812 | CRITICAL | 9.8 | 49.3% | Jul 24, 2020 | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a us... |
| CVE-2020-15860 | CRITICAL | 9.9 | 4.0% | Jul 24, 2020 | Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an ... |
| CVE-2020-15922 | CRITICAL | 9.8 | 57.3% | Jul 24, 2020 | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)... |
| CVE-2020-15921 | CRITICAL | 9.8 | 18.3% | Jul 24, 2020 | Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric... |
| CVE-2020-15920 | CRITICAL | 9.8 | 98.2% | Jul 24, 2020 | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi... |
| CVE-2020-11624 | CRITICAL | 9.8 | 1.2% | Jul 23, 2020 | An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Ind... |
| CVE-2020-15492 | CRITICAL | 9.8 | 16.6% | Jul 23, 2020 | An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we... |
| CVE-2020-15477 | CRITICAL | 9.8 | 5.0% | Jul 23, 2020 | The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters i... |
| CVE-2020-15391 | CRITICAL | 9.8 | 2.7% | Jul 23, 2020 | The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authe... |
| CVE-2020-15917 | CRITICAL | 9.8 | 2.6% | Jul 23, 2020 | common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. |
| CVE-2020-15916 | CRITICAL | 9.8 | 3.4% | Jul 23, 2020 | goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system... |
| CVE-2020-10921 | CRITICAL | 9.8 | 2.8% | Jul 23, 2020 | This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware versio... |
| CVE-2020-10920 | CRITICAL | 9.8 | 4.9% | Jul 23, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmwar... |
| CVE-2020-10917 | CRITICAL | 9.8 | 5.6% | Jul 22, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.4... |
| CVE-2020-4385 | CRITICAL | 9.8 | 1.2% | Jul 22, 2020 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which... |
| CVE-2020-9664 | CRITICAL | 9.8 | 8.4% | Jul 22, 2020 | Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exp... |
| CVE-2020-15893 | CRITICAL | 9.8 | 20.9% | Jul 22, 2020 | An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled b... |
| CVE-2020-15892 | CRITICAL | 9.8 | 1.6% | Jul 22, 2020 | An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login a... |
| CVE-2020-6522 | CRITICAL | 9.6 | 1.6% | Jul 22, 2020 | Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attac... |
| CVE-2020-6509 | CRITICAL | 9.6 | 0.8% | Jul 22, 2020 | Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install... |
| CVE-2020-6505 | CRITICAL | 9.6 | 1.0% | Jul 22, 2020 | Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sand... |
| CVE-2020-15889 | CRITICAL | 9.8 | 2.2% | Jul 21, 2020 | Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now