2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9382 | MEDIUM | 5.4 | 1.0% | Feb 24, 2020 | An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for th... |
| CVE-2020-9381 | HIGH | 7.5 | 2.1% | Feb 24, 2020 | controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/w... |
| CVE-2020-1938 | CRITICAL | 9.8 | 99.3% | Feb 24, 2020 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc... |
| CVE-2020-1935 | MEDIUM | 4.8 | 9.4% | Feb 24, 2020 | In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach t... |
| CVE-2020-1937 | HIGH | 8.8 | 2.7% | Feb 24, 2020 | Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run m... |
| CVE-2020-9374 | CRITICAL | 9.8 | 42.0% | Feb 24, 2020 | On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit... |
| CVE-2020-9369 | HIGH | 7.5 | 2.8% | Feb 24, 2020 | Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files,... |
| CVE-2020-5245 | HIGH | 8.8 | 2.8% | Feb 24, 2020 | Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privilege... |
| CVE-2020-5244 | HIGH | 7.5 | 1.9% | Feb 24, 2020 | In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Aut... |
| CVE-2020-9366 | CRITICAL | 9.8 | 2.6% | Feb 24, 2020 | A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted outp... |
| CVE-2020-9365 | HIGH | 7.5 | 6.9% | Feb 24, 2020 | An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function i... |
| CVE-2020-9363 | HIGH | 7.8 | 0.9% | Feb 24, 2020 | The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects End... |
| CVE-2020-9362 | HIGH | 7.8 | 1.5% | Feb 24, 2020 | The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. Th... |
| CVE-2020-4222 | CRITICAL | 9.8 | 15.5% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-4213 | CRITICAL | 9.8 | 15.5% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-4212 | CRITICAL | 9.8 | 15.0% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-4211 | CRITICAL | 9.8 | 71.1% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-4210 | CRITICAL | 9.8 | 15.5% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us... |
| CVE-2020-8131 | HIGH | 7.5 | 5.0% | Feb 24, 2020 | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem a... |
| CVE-2020-8130 | MEDIUM | 6.4 | 1.4% | Feb 24, 2020 | There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that be... |
| CVE-2020-5188 | MEDIUM | 6.5 | 1.8% | Feb 24, 2020 | DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. |
| CVE-2020-5187 | HIGH | 8.8 | 2.4% | Feb 24, 2020 | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). |
| CVE-2020-5186 | MEDIUM | 5.4 | 0.9% | Feb 24, 2020 | DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). |
| CVE-2020-9355 | CRITICAL | 9.8 | 2.2% | Feb 23, 2020 | danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled. |
| CVE-2020-9354 | HIGH | 7.5 | 1.2% | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functional... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now