2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26252 | HIGH | 7.2 | 2.1% | Jan 20, 2021 | OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vul... |
| CVE-2020-27859 | HIGH | 7.5 | 2.9% | Jan 20, 2021 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ESMPRO Man... |
| CVE-2020-27858 | HIGH | 7.5 | 73.8% | Jan 20, 2021 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2... |
| CVE-2020-6024 | HIGH | 7.8 | 0.3% | Jan 20, 2021 | Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and... |
| CVE-2020-28483 | HIGH | 7.1 | 1.3% | Jan 20, 2021 | This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's ... |
| CVE-2020-28452 | HIGH | 8.8 | 0.5% | Jan 20, 2021 | This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package c... |
| CVE-2020-25682 | HIGH | 8.1 | 71.0% | Jan 20, 2021 | A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names... |
| CVE-2020-25681 | HIGH | 8.1 | 81.3% | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorte... |
| CVE-2020-14360 | HIGH | 7.8 | 0.4% | Jan 20, 2021 | A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead ... |
| CVE-2020-4983 | HIGH | 7.8 | 0.4% | Jan 20, 2021 | IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to subm... |
| CVE-2020-4921 | HIGH | 8.8 | 1.5% | Jan 20, 2021 | IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL s... |
| CVE-2020-4688 | HIGH | 7.8 | 0.9% | Jan 20, 2021 | IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unpri... |
| CVE-2020-35217 | HIGH | 8.8 | 0.6% | Jan 20, 2021 | Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF toke... |
| CVE-2020-19364 | HIGH | 8.8 | 70.6% | Jan 20, 2021 | OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php. |
| CVE-2020-19360 | HIGH | 7.5 | 20.2% | Jan 20, 2021 | Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a fil... |
| CVE-2020-27264 | HIGH | 8.8 | 0.5% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and... |
| CVE-2020-14409 | HIGH | 7.8 | 1.3% | Jan 19, 2021 | SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_... |
| CVE-2020-4881 | HIGH | 7.5 | 0.9% | Jan 19, 2021 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server h... |
| CVE-2020-27733 | HIGH | 8.8 | 8.8% | Jan 19, 2021 | Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmvi... |
| CVE-2020-28482 | HIGH | 8.8 | 1.0% | Jan 19, 2021 | This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the... |
| CVE-2020-28479 | HIGH | 7.5 | 2.0% | Jan 19, 2021 | The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function. |
| CVE-2020-23342 | HIGH | 8.8 | 12.4% | Jan 19, 2021 | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. |
| CVE-2020-28478 | HIGH | 7.5 | 1.6% | Jan 19, 2021 | This affects the package gsap before 3.6.0. |
| CVE-2020-28477 | HIGH | 7.5 | 2.3% | Jan 19, 2021 | This affects all versions of package immer. |
| CVE-2020-36193 | HIGH | 7.5 | 70.6% | Jan 18, 2021 | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of sym... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now