2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9353 | HIGH | 7.5 | 1.5% | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functional... |
| CVE-2020-9352 | CRITICAL | 9.8 | 1.9% | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL fea... |
| CVE-2020-9351 | MEDIUM | 5.3 | 1.1% | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerCons... |
| CVE-2020-9350 | MEDIUM | 5.4 | 0.5% | Feb 23, 2020 | Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly. |
| CVE-2020-9342 | MEDIUM | 5.5 | 1.6% | Feb 22, 2020 | The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a ... |
| CVE-2020-9341 | HIGH | 8.8 | 0.6% | Feb 22, 2020 | CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&... |
| CVE-2020-9340 | HIGH | 7.2 | 1.0% | Feb 22, 2020 | fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter. |
| CVE-2020-9339 | MEDIUM | 5.4 | 0.6% | Feb 22, 2020 | SOPlanning 1.45 allows XSS via the Name or Comment to status.php. |
| CVE-2020-9338 | MEDIUM | 5.4 | 0.5% | Feb 22, 2020 | SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field. |
| CVE-2020-9336 | MEDIUM | 5.4 | 0.5% | Feb 22, 2020 | fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field... |
| CVE-2020-9039 | CRITICAL | 9.8 | 3.8% | Feb 22, 2020 | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Per... |
| CVE-2020-8813 | HIGH | 8.8 | 73.8% | Feb 22, 2020 | graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a... |
| CVE-2020-8862 | HIGH | 8.8 | 13.3% | Feb 22, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-26... |
| CVE-2020-8861 | HIGH | 8.8 | 6.5% | Feb 22, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-13... |
| CVE-2020-8860 | HIGH | 8 | 0.7% | Feb 22, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Fir... |
| CVE-2020-9330 | HIGH | 8.8 | 1.1% | Feb 21, 2020 | Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind cred... |
| CVE-2020-9329 | MEDIUM | 5.9 | 0.7% | Feb 21, 2020 | Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go ... |
| CVE-2020-9327 | HIGH | 7.5 | 3.7% | Feb 21, 2020 | In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault ... |
| CVE-2020-7907 | HIGH | 7.5 | 0.8% | Feb 21, 2020 | In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections. |
| CVE-2020-6842 | HIGH | 7.2 | 2.3% | Feb 21, 2020 | D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell... |
| CVE-2020-6841 | CRITICAL | 9.8 | 2.8% | Feb 21, 2020 | D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharac... |
| CVE-2020-5326 | MEDIUM | 5.3 | 0.3% | Feb 21, 2020 | Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot In... |
| CVE-2020-5324 | MEDIUM | 4.4 | 0.3% | Feb 21, 2020 | Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is li... |
| CVE-2020-5534 | HIGH | 8 | 0.9% | Feb 21, 2020 | Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arb... |
| CVE-2020-5533 | MEDIUM | 6.1 | 0.8% | Feb 21, 2020 | Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arb... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now