2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10806 | CRITICAL | 9.8 | 2.3% | Mar 22, 2020 | eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 20... |
| CVE-2020-10803 | MEDIUM | 5.4 | 1.6% | Mar 22, 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code c... |
| CVE-2020-10802 | HIGH | 8 | 2.1% | Mar 22, 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain par... |
| CVE-2020-10804 | HIGH | 8 | 2.7% | Mar 22, 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current... |
| CVE-2020-10800 | HIGH | 8.1 | 1.4% | Mar 21, 2020 | lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data... |
| CVE-2020-10799 | CRITICAL | 9.8 | 1.4% | Mar 20, 2020 | The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call. |
| CVE-2020-8140 | MEDIUM | 6.7 | 0.7% | Mar 20, 2020 | A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client wit... |
| CVE-2020-8139 | MEDIUM | 6.5 | 1.5% | Mar 20, 2020 | A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be do... |
| CVE-2020-8138 | MEDIUM | 6.5 | 1.4% | Mar 20, 2020 | A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side ... |
| CVE-2020-10194 | MEDIUM | 6.5 | 1.2% | Mar 20, 2020 | cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any ... |
| CVE-2020-8883 | MEDIUM | 4.3 | 8.4% | Mar 20, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P... |
| CVE-2020-8882 | HIGH | 8.8 | 11.1% | Mar 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8881 | HIGH | 8.8 | 11.1% | Mar 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8880 | HIGH | 8.8 | 11.1% | Mar 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8879 | MEDIUM | 4.3 | 8.2% | Mar 20, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P... |
| CVE-2020-8878 | HIGH | 8.8 | 11.1% | Mar 20, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2020-8877 | MEDIUM | 4.3 | 8.2% | Mar 20, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P... |
| CVE-2020-8137 | CRITICAL | 9.8 | 4.2% | Mar 20, 2020 | Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be contr... |
| CVE-2020-8136 | HIGH | 7.5 | 1.5% | Mar 20, 2020 | Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing ... |
| CVE-2020-8135 | CRITICAL | 9.8 | 1.3% | Mar 20, 2020 | The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attack... |
| CVE-2020-8134 | HIGH | 8.1 | 1.2% | Mar 20, 2020 | Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external netw... |
| CVE-2020-7961 | CRITICAL | 9.8 | 99.8% | Mar 20, 2020 | Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c... |
| CVE-2020-10558 | MEDIUM | 6.5 | 2.6% | Mar 20, 2020 | The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to... |
| CVE-2020-9425 | HIGH | 7.5 | 16.7% | Mar 20, 2020 | An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved... |
| CVE-2020-10792 | HIGH | 7.5 | 1.9% | Mar 20, 2020 | openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placin... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now