2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15801 | CRITICAL | 9.8 | 3.1% | Jul 17, 2020 | In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from ar... |
| CVE-2020-9682 | CRITICAL | 9.8 | 4.3% | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful... |
| CVE-2020-9671 | CRITICAL | 9.8 | 4.0% | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Succe... |
| CVE-2020-9670 | CRITICAL | 9.8 | 3.6% | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful... |
| CVE-2020-9669 | CRITICAL | 9.8 | 3.4% | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Succ... |
| CVE-2020-11982 | CRITICAL | 9.8 | 7.2% | Jul 17, 2020 | An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to ... |
| CVE-2020-11981 | CRITICAL | 9.8 | 34.0% | Jul 17, 2020 | An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect t... |
| CVE-2020-12013 | CRITICAL | 9.1 | 3.0% | Jul 16, 2020 | A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely... |
| CVE-2020-12007 | CRITICAL | 9.8 | 3.9% | Jul 16, 2020 | A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-... |
| CVE-2020-12011 | CRITICAL | 9.8 | 29.2% | Jul 16, 2020 | A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow... |
| CVE-2020-3357 | CRITICAL | 9.8 | 4.2% | Jul 16, 2020 | A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Small Business RV340, RV340W, RV345, and RV345P D... |
| CVE-2020-3331 | CRITICAL | 9.8 | 43.6% | Jul 16, 2020 | A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-... |
| CVE-2020-3330 | CRITICAL | 9.8 | 3.4% | Jul 16, 2020 | A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unau... |
| CVE-2020-3323 | CRITICAL | 9.8 | 5.7% | Jul 16, 2020 | A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers ... |
| CVE-2020-3144 | CRITICAL | 9.8 | 2.9% | Jul 16, 2020 | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV1... |
| CVE-2020-3140 | CRITICAL | 9.8 | 3.1% | Jul 16, 2020 | A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthentic... |
| CVE-2020-15027 | CRITICAL | 9.8 | 1.3% | Jul 16, 2020 | ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication... |
| CVE-2020-14000 | CRITICAL | 9.8 | 2.8% | Jul 16, 2020 | MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted ... |
| CVE-2020-10288 | CRITICAL | 9.8 | 1.5% | Jul 15, 2020 | IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and p... |
| CVE-2020-10287 | CRITICAL | 9.8 | 1.4% | Jul 15, 2020 | The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manua... |
| CVE-2020-10285 | CRITICAL | 9.8 | 1.3% | Jul 15, 2020 | The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force att... |
| CVE-2020-12684 | CRITICAL | 9.8 | 1.1% | Jul 15, 2020 | XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, w... |
| CVE-2020-11436 | CRITICAL | 9 | 1.3% | Jul 15, 2020 | LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other us... |
| CVE-2020-10284 | CRITICAL | 9.1 | 1.4% | Jul 15, 2020 | No authentication is required to control the robot inside the network, moreso the latest available user manual shows an ... |
| CVE-2020-14705 | CRITICAL | 9.6 | 1.9% | Jul 15, 2020 | Vulnerability in the Oracle GoldenGate product of Oracle GoldenGate (component: Process Management). The supported versi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now