2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3922 | CRITICAL | 9.8 | 1.5% | Mar 18, 2020 | LisoMail, by ArmorX, allows SQL Injections, attackers can access the database without authentication via a URL parameter... |
| CVE-2020-10659 | MEDIUM | 4.3 | 0.4% | Mar 18, 2020 | Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validati... |
| CVE-2020-8600 | CRITICAL | 9.8 | 4.2% | Mar 18, 2020 | Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could ... |
| CVE-2020-8599 | CRITICAL | 9.8 | 11.6% | Mar 18, 2020 | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to... |
| CVE-2020-8598 | CRITICAL | 9.8 | 13.2% | Mar 18, 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl... |
| CVE-2020-8470 | HIGH | 7.5 | 4.5% | Mar 18, 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl... |
| CVE-2020-8468 | HIGH | 8.8 | 5.8% | Mar 18, 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a co... |
| CVE-2020-8467 | HIGH | 8.8 | 10.8% | Mar 18, 2020 | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow r... |
| CVE-2020-3951 | LOW | 3.8 | 0.3% | Mar 17, 2020 | VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-... |
| CVE-2020-3950 | HIGH | 7.8 | 7.3% | Mar 17, 2020 | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for ... |
| CVE-2020-1720 | MEDIUM | 6.5 | 1.2% | Mar 17, 2020 | A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization chec... |
| CVE-2020-10596 | MEDIUM | 5.4 | 2.7% | Mar 17, 2020 | OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upl... |
| CVE-2020-10122 | MEDIUM | 6.5 | 0.9% | Mar 17, 2020 | cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547). |
| CVE-2020-10121 | CRITICAL | 9.8 | 1.8% | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546). |
| CVE-2020-10120 | HIGH | 7.2 | 2.7% | Mar 17, 2020 | cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545). |
| CVE-2020-10119 | CRITICAL | 9.8 | 2.2% | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). |
| CVE-2020-10118 | CRITICAL | 9.1 | 1.0% | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543). |
| CVE-2020-10117 | CRITICAL | 9.1 | 1.0% | Mar 17, 2020 | cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542). |
| CVE-2020-10116 | MEDIUM | 5.3 | 0.8% | Mar 17, 2020 | cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI ca... |
| CVE-2020-10115 | HIGH | 7.2 | 1.8% | Mar 17, 2020 | cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). |
| CVE-2020-10114 | MEDIUM | 6.1 | 0.6% | Mar 17, 2020 | cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). |
| CVE-2020-10113 | MEDIUM | 6.1 | 0.6% | Mar 17, 2020 | cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515). |
| CVE-2020-10380 | CRITICAL | 9.8 | 1.1% | Mar 17, 2020 | RMySQL through 0.10.19 allows SQL Injection. |
| CVE-2020-6646 | MEDIUM | 5.4 | 0.8% | Mar 17, 2020 | An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored... |
| CVE-2020-9347 | CRITICAL | 9.8 | 7.8% | Mar 16, 2020 | Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name tha... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now