2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25533 | HIGH | 7 | 0.3% | Jan 15, 2021 | An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged ac... |
| CVE-2020-24641 | HIGH | 7.5 | 1.5% | Jan 15, 2021 | In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated end... |
| CVE-2020-24638 | HIGH | 7.2 | 3.2% | Jan 15, 2021 | Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. Thes... |
| CVE-2020-35749 | HIGH | 7.7 | 30.5% | Jan 15, 2021 | Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2... |
| CVE-2020-35733 | HIGH | 7.5 | 1.2% | Jan 15, 2021 | An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certif... |
| CVE-2020-27220 | HIGH | 8.8 | 1.1% | Jan 14, 2021 | The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to r... |
| CVE-2020-6572 | HIGH | 8.8 | 10.6% | Jan 14, 2021 | Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a... |
| CVE-2020-29494 | HIGH | 8.7 | 1.7% | Jan 14, 2021 | Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could po... |
| CVE-2020-6776 | HIGH | 8.8 | 0.5% | Jan 14, 2021 | A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAE... |
| CVE-2020-29018 | HIGH | 8.8 | 2.0% | Jan 14, 2021 | A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the co... |
| CVE-2020-29017 | HIGH | 8.8 | 3.6% | Jan 14, 2021 | An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to ... |
| CVE-2020-26732 | HIGH | 7.5 | 1.5% | Jan 14, 2021 | SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie ... |
| CVE-2020-16119 | HIGH | 7.8 | 0.4% | Jan 14, 2021 | Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an a... |
| CVE-2020-14102 | HIGH | 7.2 | 1.9% | Jan 13, 2021 | There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root priv... |
| CVE-2020-14101 | HIGH | 7.5 | 1.1% | Jan 13, 2021 | The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi rout... |
| CVE-2020-14098 | HIGH | 7.5 | 1.2% | Jan 13, 2021 | The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts.... |
| CVE-2020-14097 | HIGH | 7.5 | 0.9% | Jan 13, 2021 | Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6... |
| CVE-2020-35578 | HIGH | 7.2 | 81.9% | Jan 13, 2021 | An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature... |
| CVE-2020-4596 | HIGH | 7.5 | 0.8% | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to ... |
| CVE-2020-4595 | HIGH | 7.5 | 0.8% | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to ... |
| CVE-2020-4594 | HIGH | 7.5 | 0.8% | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to ... |
| CVE-2020-26262 | HIGH | 7.2 | 1.3% | Jan 13, 2021 | Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow... |
| CVE-2020-5686 | HIGH | 7.5 | 1.2% | Jan 13, 2021 | Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from... |
| CVE-2020-35686 | HIGH | 7.8 | 0.3% | Jan 13, 2021 | The SECOMN service in Sound Research DCHU model software component modules (APO) through 2.0.9.17, delivered on HP Windo... |
| CVE-2020-28374 | HIGH | 8.1 | 6.6% | Jan 13, 2021 | In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCS... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now