2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6059 | HIGH | 8.2 | 2.6% | Feb 4, 2020 | An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A ... |
| CVE-2020-6058 | CRITICAL | 9.1 | 2.4% | Feb 4, 2020 | An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A ... |
| CVE-2020-7221 | HIGH | 7.8 | 0.7% | Feb 4, 2020 | mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root becau... |
| CVE-2020-4163 | HIGH | 7.2 | 1.6% | Feb 4, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user... |
| CVE-2020-3939 | MEDIUM | 6.1 | 0.7% | Feb 4, 2020 | SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Cross-Site Scripting(XSS), personal informa... |
| CVE-2020-3938 | HIGH | 7.5 | 1.5% | Feb 4, 2020 | SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to laun... |
| CVE-2020-3937 | HIGH | 7.5 | 1.4% | Feb 4, 2020 | SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries ... |
| CVE-2020-5236 | MEDIUM | 6.5 | 2.6% | Feb 4, 2020 | Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a head... |
| CVE-2020-5235 | CRITICAL | 9.8 | 1.7% | Feb 4, 2020 | There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is ... |
| CVE-2020-8597 | CRITICAL | 9.8 | 19.4% | Feb 3, 2020 | eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. |
| CVE-2020-8592 | CRITICAL | 9.8 | 1.4% | Feb 3, 2020 | eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password featu... |
| CVE-2020-8591 | CRITICAL | 9.8 | 1.4% | Feb 3, 2020 | eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r re... |
| CVE-2020-8549 | MEDIUM | 6.1 | 1.9% | Feb 3, 2020 | Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious ... |
| CVE-2020-8548 | MEDIUM | 6.1 | 1.4% | Feb 3, 2020 | massCode 1.0.0-alpha.6 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegrati... |
| CVE-2020-5182 | MEDIUM | 6.5 | 1.0% | Feb 3, 2020 | The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link t... |
| CVE-2020-4224 | MEDIUM | 5.5 | 0.2% | Feb 3, 2020 | IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain direc... |
| CVE-2020-8547 | CRITICAL | 9.8 | 5.9% | Feb 3, 2020 | phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which m... |
| CVE-2020-8545 | HIGH | 7.5 | 1.3% | Feb 3, 2020 | Global.py in AIL framework 2.8 allows path traversal. |
| CVE-2020-8510 | CRITICAL | 9.8 | 1.2% | Feb 3, 2020 | An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of... |
| CVE-2020-7993 | MEDIUM | 4.3 | 0.7% | Feb 3, 2020 | Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a mo... |
| CVE-2020-7471 | CRITICAL | 9.8 | 65.3% | Feb 3, 2020 | Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a ... |
| CVE-2020-3927 | HIGH | 7.5 | 1.2% | Feb 3, 2020 | An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific ... |
| CVE-2020-3926 | HIGH | 7.5 | 1.5% | Feb 3, 2020 | An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific ... |
| CVE-2020-3925 | HIGH | 8.8 | 2.8% | Feb 3, 2020 | A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long ... |
| CVE-2020-8508 | CRITICAL | 9.8 | 1.7% | Feb 3, 2020 | nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of func... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now