2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3922CRITICAL9.8LisoMail, by ArmorX, allows SQL Injections, attackers can access the database without authentication via a URL parameter...
CVE-2020-10659MEDIUM4.3Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validati...
CVE-2020-8600CRITICAL9.8Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could ...
CVE-2020-8599CRITICAL9.8Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to...
CVE-2020-8598CRITICAL9.8Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl...
CVE-2020-8470HIGH7.5Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl...
CVE-2020-8468HIGH8.8Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a co...
CVE-2020-8467HIGH8.8A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow r...
CVE-2020-3951LOW3.8VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-...
CVE-2020-3950HIGH7.8VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for ...
CVE-2020-1720MEDIUM6.5A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization chec...
CVE-2020-10596MEDIUM5.4OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upl...
CVE-2020-10122MEDIUM6.5cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).
CVE-2020-10121CRITICAL9.8cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
CVE-2020-10120HIGH7.2cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
CVE-2020-10119CRITICAL9.8cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
CVE-2020-10118CRITICAL9.1cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).
CVE-2020-10117CRITICAL9.1cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
CVE-2020-10116MEDIUM5.3cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI ca...
CVE-2020-10115HIGH7.2cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
CVE-2020-10114MEDIUM6.1cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
CVE-2020-10113MEDIUM6.1cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
CVE-2020-10380CRITICAL9.8RMySQL through 0.10.19 allows SQL Injection.
CVE-2020-6646MEDIUM5.4An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored...
CVE-2020-9347CRITICAL9.8Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name tha...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now