2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10938 | CRITICAL | 9.8 | 5.2% | Mar 24, 2020 | GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in m... |
| CVE-2020-10385 | MEDIUM | 5.4 | 4.4% | Mar 24, 2020 | A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.... |
| CVE-2020-1747 | CRITICAL | 9.8 | 5.3% | Mar 24, 2020 | A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code... |
| CVE-2020-10934 | HIGH | 7.2 | 1.3% | Mar 24, 2020 | Acyba AcyMailing before 6.9.2 mishandles file uploads by admins. |
| CVE-2020-10931 | HIGH | 7.5 | 28.1% | Mar 24, 2020 | Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary pr... |
| CVE-2020-9359 | MEDIUM | 5.3 | 1.5% | Mar 24, 2020 | KDE Okular before 1.10.0 allows code execution via an action link in a PDF document. |
| CVE-2020-1744 | MEDIUM | 5.6 | 1.1% | Mar 24, 2020 | A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post log... |
| CVE-2020-10684 | HIGH | 7.1 | 0.3% | Mar 24, 2020 | A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, w... |
| CVE-2020-10570 | MEDIUM | 6.1 | 0.4% | Mar 24, 2020 | The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attacker... |
| CVE-2020-5252 | MEDIUM | 4.1 | 0.4% | Mar 23, 2020 | The command-line "safety" package for Python has a potential security issue. There are two Python characteristics that a... |
| CVE-2020-1944 | CRITICAL | 9.8 | 2.7% | Mar 23, 2020 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling at... |
| CVE-2020-10879 | CRITICAL | 9.8 | 83.9% | Mar 23, 2020 | rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nod... |
| CVE-2020-10875 | HIGH | 7.5 | 1.7% | Mar 23, 2020 | Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Ser... |
| CVE-2020-8868 | CRITICAL | 9.8 | 9.5% | Mar 23, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve ... |
| CVE-2020-8866 | MEDIUM | 6.5 | 9.6% | Mar 23, 2020 | This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmai... |
| CVE-2020-8865 | MEDIUM | 6.3 | 6.8% | Mar 23, 2020 | This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webma... |
| CVE-2020-8864 | HIGH | 8.8 | 80.2% | Mar 23, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86... |
| CVE-2020-8863 | HIGH | 8.8 | 76.7% | Mar 23, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86... |
| CVE-2020-8859 | HIGH | 7.5 | 3.5% | Mar 23, 2020 | This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ELOG Ele... |
| CVE-2020-6967 | CRITICAL | 9.8 | 5.4% | Mar 23, 2020 | In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platfor... |
| CVE-2020-10874 | HIGH | 7.5 | 1.4% | Mar 23, 2020 | Motorola FX9500 devices allow remote attackers to read database files. |
| CVE-2020-7482 | MEDIUM | 6.1 | 0.8% | Mar 23, 2020 | A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andov... |
| CVE-2020-7481 | MEDIUM | 6.1 | 0.8% | Mar 23, 2020 | A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andov... |
| CVE-2020-7480 | CRITICAL | 9.8 | 1.5% | Mar 23, 2020 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versi... |
| CVE-2020-7479 | HIGH | 7.8 | 0.5% | Mar 23, 2020 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the se... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now