2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6425 | MEDIUM | 5.4 | 1.2% | Mar 23, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced ... |
| CVE-2020-6424 | HIGH | 8.8 | 3.5% | Mar 23, 2020 | Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-6422 | HIGH | 8.8 | 2.4% | Mar 23, 2020 | Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-6420 | HIGH | 8.8 | 1.3% | Mar 23, 2020 | Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass sam... |
| CVE-2020-10364 | HIGH | 7.5 | 2.6% | Mar 23, 2020 | The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusa... |
| CVE-2020-8497 | MEDIUM | 5.3 | 5.3% | Mar 23, 2020 | In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format an... |
| CVE-2020-10793 | HIGH | 8.8 | 1.9% | Mar 23, 2020 | CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the ... |
| CVE-2020-6650 | HIGH | 8.8 | 2.1% | Mar 23, 2020 | UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or ... |
| CVE-2020-1951 | MEDIUM | 5.5 | 2.7% | Mar 23, 2020 | A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. |
| CVE-2020-1950 | MEDIUM | 5.5 | 2.6% | Mar 23, 2020 | A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23... |
| CVE-2020-10661 | CRITICAL | 9.1 | 1.1% | Mar 23, 2020 | HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing neste... |
| CVE-2020-10660 | MEDIUM | 5.3 | 0.8% | Mar 23, 2020 | HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Gro... |
| CVE-2020-10593 | HIGH | 7.5 | 2.3% | Mar 23, 2020 | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Servi... |
| CVE-2020-10592 | HIGH | 7.5 | 3.1% | Mar 23, 2020 | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Servi... |
| CVE-2020-9752 | CRITICAL | 9.8 | 1.1% | Mar 23, 2020 | Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system... |
| CVE-2020-10821 | MEDIUM | 4.8 | 73.6% | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter. |
| CVE-2020-10820 | MEDIUM | 4.8 | 30.1% | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter. |
| CVE-2020-10819 | MEDIUM | 4.8 | 73.8% | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter. |
| CVE-2020-10818 | HIGH | 7.2 | 2.9% | Mar 22, 2020 | Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the ... |
| CVE-2020-10812 | MEDIUM | 5.5 | 1.5% | Mar 22, 2020 | An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() locate... |
| CVE-2020-10811 | MEDIUM | 5.5 | 1.4% | Mar 22, 2020 | An issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5O__layout_decode(... |
| CVE-2020-10810 | MEDIUM | 5.5 | 1.4% | Mar 22, 2020 | An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5AC_unpin_entry() loc... |
| CVE-2020-10809 | MEDIUM | 5.5 | 1.5% | Mar 22, 2020 | An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located... |
| CVE-2020-10808 | HIGH | 8.8 | 77.3% | Mar 22, 2020 | Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint.... |
| CVE-2020-10807 | MEDIUM | 5.3 | 1.4% | Mar 22, 2020 | auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now