2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15866 | CRITICAL | 9.8 | 2.1% | Jul 21, 2020 | mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrec... |
| CVE-2020-6103 | CRITICAL | 9.9 | 2.8% | Jul 20, 2020 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.... |
| CVE-2020-6102 | CRITICAL | 9.9 | 2.8% | Jul 20, 2020 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.... |
| CVE-2020-6101 | CRITICAL | 9.9 | 2.8% | Jul 20, 2020 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.... |
| CVE-2020-6100 | CRITICAL | 9.9 | 2.1% | Jul 20, 2020 | An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially... |
| CVE-2020-6871 | CRITICAL | 9.8 | 1.9% | Jul 20, 2020 | The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the a... |
| CVE-2020-15123 | CRITICAL | 9.3 | 3.8% | Jul 20, 2020 | In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the co... |
| CVE-2020-15121 | CRITICAL | 9.6 | 1.6% | Jul 20, 2020 | In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the p... |
| CVE-2020-14494 | CRITICAL | 9.8 | 1.3% | Jul 20, 2020 | OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide ... |
| CVE-2020-14485 | CRITICAL | 9.8 | 2.5% | Jul 20, 2020 | OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted... |
| CVE-2020-14484 | CRITICAL | 9.8 | 1.2% | Jul 20, 2020 | OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, whi... |
| CVE-2020-7206 | CRITICAL | 9.8 | 1.7% | Jul 17, 2020 | HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability. |
| CVE-2020-5759 | CRITICAL | 9.8 | 3.2% | Jul 17, 2020 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authen... |
| CVE-2020-5757 | CRITICAL | 9.8 | 6.9% | Jul 17, 2020 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authe... |
| CVE-2020-0231 | CRITICAL | 9.8 | 0.4% | Jul 17, 2020 | There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid I... |
| CVE-2020-0230 | CRITICAL | 9.8 | 0.5% | Jul 17, 2020 | There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid I... |
| CVE-2020-0225 | CRITICAL | 9.8 | 2.7% | Jul 17, 2020 | In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to... |
| CVE-2020-0224 | CRITICAL | 9.8 | 1.6% | Jul 17, 2020 | In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could... |
| CVE-2020-1654 | CRITICAL | 9.8 | 2.2% | Jul 17, 2020 | On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a m... |
| CVE-2020-1652 | CRITICAL | 9.8 | 0.7% | Jul 17, 2020 | OpenNMS is accessible via port 9443 |
| CVE-2020-1647 | CRITICAL | 9.8 | 2.6% | Jul 17, 2020 | On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free ... |
| CVE-2020-7826 | CRITICAL | 9.8 | 0.7% | Jul 17, 2020 | EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be ... |
| CVE-2020-7825 | CRITICAL | 9.8 | 2.1% | Jul 17, 2020 | A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05... |
| CVE-2020-14001 | CRITICAL | 9.8 | 4.5% | Jul 17, 2020 | The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows ... |
| CVE-2020-7684 | CRITICAL | 9.8 | 1.5% | Jul 17, 2020 | This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now