2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9449 | HIGH | 8.8 | 1.0% | Feb 28, 2020 | An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (clien... |
| CVE-2020-9466 | MEDIUM | 6.1 | 1.3% | Feb 28, 2020 | The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection. |
| CVE-2020-9465 | CRITICAL | 9.8 | 82.2% | Feb 28, 2020 | An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL... |
| CVE-2020-8132 | CRITICAL | 9.8 | 2.0% | Feb 28, 2020 | Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF fi... |
| CVE-2020-8127 | MEDIUM | 6.1 | 1.2% | Feb 28, 2020 | Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attacke... |
| CVE-2020-1881 | HIGH | 7.5 | 0.8% | Feb 28, 2020 | NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have have ... |
| CVE-2020-1877 | MEDIUM | 4.4 | 0.2% | Feb 28, 2020 | NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid poi... |
| CVE-2020-1876 | HIGH | 7.5 | 0.8% | Feb 28, 2020 | NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-boun... |
| CVE-2020-1875 | MEDIUM | 5.5 | 0.2% | Feb 28, 2020 | NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid... |
| CVE-2020-1874 | MEDIUM | 5.5 | 0.2% | Feb 28, 2020 | NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid ... |
| CVE-2020-1873 | HIGH | 7.5 | 0.8% | Feb 28, 2020 | NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an ou... |
| CVE-2020-1861 | MEDIUM | 4.4 | 0.2% | Feb 28, 2020 | CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PW... |
| CVE-2020-1860 | HIGH | 7.5 | 0.7% | Feb 28, 2020 | NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an ac... |
| CVE-2020-1844 | HIGH | 7.8 | 0.2% | Feb 28, 2020 | PCManager with versions earlier than 10.0.5.51 have a privilege escalation vulnerability in Huawei PCManager products. A... |
| CVE-2020-1792 | MEDIUM | 5.5 | 0.5% | Feb 28, 2020 | Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0... |
| CVE-2020-9463 | HIGH | 8.8 | 4.1% | Feb 28, 2020 | Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server... |
| CVE-2020-5247 | HIGH | 7.5 | 2.5% | Feb 28, 2020 | In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response head... |
| CVE-2020-9447 | MEDIUM | 6.1 | 0.7% | Feb 28, 2020 | There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can up... |
| CVE-2020-9442 | HIGH | 7.8 | 0.6% | Feb 28, 2020 | OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10,... |
| CVE-2020-9399 | MEDIUM | 5.5 | 1.1% | Feb 28, 2020 | The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 def... |
| CVE-2020-9434 | CRITICAL | 9.1 | 0.8% | Feb 27, 2020 | openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean... |
| CVE-2020-9433 | CRITICAL | 9.1 | 0.8% | Feb 27, 2020 | openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean ... |
| CVE-2020-9432 | CRITICAL | 9.1 | 0.8% | Feb 27, 2020 | openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean f... |
| CVE-2020-9431 | HIGH | 7.5 | 2.7% | Feb 27, 2020 | In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addr... |
| CVE-2020-9430 | HIGH | 7.5 | 2.8% | Feb 27, 2020 | In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addres... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now