2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9346 | HIGH | 8.8 | 2.5% | Mar 16, 2020 | Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attack... |
| CVE-2020-8787 | HIGH | 7.5 | 0.9% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submit... |
| CVE-2020-8786 | CRITICAL | 9.8 | 1.1% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4). |
| CVE-2020-8785 | CRITICAL | 9.8 | 1.1% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4). |
| CVE-2020-8784 | CRITICAL | 9.8 | 1.1% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4). |
| CVE-2020-8783 | CRITICAL | 9.8 | 1.1% | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4). |
| CVE-2020-7982 | HIGH | 8.1 | 1.6% | Mar 16, 2020 | An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the... |
| CVE-2020-7919 | HIGH | 7.5 | 2.6% | Mar 16, 2020 | Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 f... |
| CVE-2020-7248 | HIGH | 7.5 | 2.5% | Mar 16, 2020 | libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that... |
| CVE-2020-6175 | MEDIUM | 5.9 | 0.6% | Mar 16, 2020 | Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. |
| CVE-2020-9472 | MEDIUM | 6.5 | 2.1% | Mar 16, 2020 | Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package f... |
| CVE-2020-9471 | HIGH | 8.8 | 2.3% | Mar 16, 2020 | Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package... |
| CVE-2020-7608 | MEDIUM | 5.3 | 0.5% | Mar 16, 2020 | yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload. |
| CVE-2020-9321 | HIGH | 7.5 | 0.7% | Mar 16, 2020 | configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents f... |
| CVE-2020-7916 | MEDIUM | 6.5 | 1.1% | Mar 16, 2020 | be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered u... |
| CVE-2020-6582 | HIGH | 7.5 | 3.9% | Mar 16, 2020 | Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a la... |
| CVE-2020-6581 | HIGH | 7.3 | 1.6% | Mar 16, 2020 | Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and ... |
| CVE-2020-5849 | HIGH | 7.5 | 93.2% | Mar 16, 2020 | Unraid 6.8.0 allows authentication bypass. |
| CVE-2020-5847 | CRITICAL | 9.8 | 95.8% | Mar 16, 2020 | Unraid through 6.8.0 allows Remote Code Execution. |
| CVE-2020-5844 | HIGH | 7.2 | 30.3% | Mar 16, 2020 | index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t... |
| CVE-2020-3948 | HIGH | 7.8 | 0.3% | Mar 16, 2020 | Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privi... |
| CVE-2020-3947 | HIGH | 8.8 | 0.6% | Mar 16, 2020 | VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. ... |
| CVE-2020-6990 | CRITICAL | 9.8 | 4.2% | Mar 16, 2020 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont... |
| CVE-2020-6988 | HIGH | 7.5 | 3.9% | Mar 16, 2020 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont... |
| CVE-2020-6984 | HIGH | 7.5 | 2.8% | Mar 16, 2020 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now