2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10180 | CRITICAL | 9.8 | 1.6% | Mar 5, 2020 | The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects ve... |
| CVE-2020-5250 | MEDIUM | 6.3 | 0.9% | Mar 5, 2020 | In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the ... |
| CVE-2020-9418 | HIGH | 7.8 | 0.4% | Mar 5, 2020 | An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attack... |
| CVE-2020-8994 | MEDIUM | 6.8 | 0.6% | Mar 5, 2020 | An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing t... |
| CVE-2020-4278 | HIGH | 7.8 | 0.3% | Mar 5, 2020 | IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user... |
| CVE-2020-10174 | HIGH | 7 | 0.3% | Mar 5, 2020 | init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the pr... |
| CVE-2020-9544 | HIGH | 7.5 | 1.4% | Mar 5, 2020 | An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authenticat... |
| CVE-2020-9402 | HIGH | 8.8 | 22.5% | Mar 5, 2020 | Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a ... |
| CVE-2020-10173 | HIGH | 8.8 | 77.3% | Mar 5, 2020 | Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabiliti... |
| CVE-2020-9380 | CRITICAL | 9.8 | 4.0% | Mar 5, 2020 | IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script. |
| CVE-2020-9370 | CRITICAL | 9.1 | 1.2% | Mar 5, 2020 | HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking. |
| CVE-2020-10107 | MEDIUM | 5.4 | 0.5% | Mar 5, 2020 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCo... |
| CVE-2020-10106 | CRITICAL | 9.8 | 1.2% | Mar 5, 2020 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in in... |
| CVE-2020-10105 | MEDIUM | 5.3 | 0.9% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS... |
| CVE-2020-10104 | MEDIUM | 4.3 | 0.8% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user ... |
| CVE-2020-10103 | MEDIUM | 5.4 | 0.5% | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t... |
| CVE-2020-10102 | MEDIUM | 5.3 | 0.7% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would ... |
| CVE-2020-10101 | HIGH | 7.5 | 1.1% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sen... |
| CVE-2020-10100 | MEDIUM | 6.5 | 0.9% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with s... |
| CVE-2020-10099 | MEDIUM | 5.4 | 0.5% | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t... |
| CVE-2020-10098 | MEDIUM | 5.4 | 0.5% | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t... |
| CVE-2020-10097 | MEDIUM | 5.3 | 0.9% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal app... |
| CVE-2020-10096 | HIGH | 7.5 | 1.1% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memor... |
| CVE-2020-8660 | MEDIUM | 5.3 | 0.6% | Mar 4, 2020 | CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) ... |
| CVE-2020-8664 | MEDIUM | 5.3 | 1.3% | Mar 4, 2020 | CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same s... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now