2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9297 | CRITICAL | 9.8 | 1.7% | Jul 14, 2020 | Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint valida... |
| CVE-2020-11546 | CRITICAL | 9.8 | 31.7% | Jul 14, 2020 | SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing... |
| CVE-2020-7593 | CRITICAL | 9.8 | 9.1% | Jul 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLU... |
| CVE-2020-1948 | CRITICAL | 9.8 | 13.9% | Jul 14, 2020 | This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unr... |
| CVE-2020-13753 | CRITICAL | 10 | 2.9% | Jul 14, 2020 | The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER an... |
| CVE-2020-11956 | CRITICAL | 9.8 | 1.6% | Jul 14, 2020 | An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is ... |
| CVE-2020-10042 | CRITICAL | 9.8 | 1.9% | Jul 14, 2020 | A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions... |
| CVE-2020-10038 | CRITICAL | 9.8 | 1.2% | Jul 14, 2020 | A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions... |
| CVE-2020-6287 | CRITICAL | 10 | 94.7% | Jul 14, 2020 | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c... |
| CVE-2020-13926 | CRITICAL | 9.8 | 1.9% | Jul 14, 2020 | Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is f... |
| CVE-2020-13925 | CRITICAL | 9.8 | 19.9% | Jul 14, 2020 | Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then exe... |
| CVE-2020-11951 | CRITICAL | 9.8 | 1.7% | Jul 14, 2020 | An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is ... |
| CVE-2020-10988 | CRITICAL | 9.8 | 2.8% | Jul 13, 2020 | A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated... |
| CVE-2020-10987 | CRITICAL | 9.8 | 79.7% | Jul 13, 2020 | The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary s... |
| CVE-2020-11749 | CRITICAL | 9 | 16.2% | Jul 13, 2020 | Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator ... |
| CVE-2020-15504 | CRITICAL | 9.8 | 2.2% | Jul 10, 2020 | A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially... |
| CVE-2020-8186 | CRITICAL | 9.8 | 2.8% | Jul 10, 2020 | A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pas... |
| CVE-2020-7815 | CRITICAL | 9.8 | 1.2% | Jul 10, 2020 | XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by settin... |
| CVE-2020-7814 | CRITICAL | 9.8 | 1.2% | Jul 10, 2020 | RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and ex... |
| CVE-2020-7692 | CRITICAL | 9.1 | 1.6% | Jul 9, 2020 | PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the a... |
| CVE-2020-7458 | CRITICAL | 9.8 | 1.9% | Jul 9, 2020 | In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-c... |
| CVE-2020-11849 | CRITICAL | 9.8 | 1.2% | Jul 8, 2020 | Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prio... |
| CVE-2020-3931 | CRITICAL | 9.8 | 1.8% | Jul 8, 2020 | Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute ar... |
| CVE-2020-8521 | CRITICAL | 9.8 | 1.4% | Jul 7, 2020 | SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with a... |
| CVE-2020-8520 | CRITICAL | 9.8 | 1.4% | Jul 7, 2020 | SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with aja... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now