2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8443 | CRITICAL | 9.8 | 2.7% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an... |
| CVE-2020-8442 | HIGH | 8.8 | 2.4% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ... |
| CVE-2020-8438 | HIGH | 7.2 | 1.6% | Jan 29, 2020 | Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hid... |
| CVE-2020-8432 | CRITICAL | 9.8 | 3.7% | Jan 29, 2020 | In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double free... |
| CVE-2020-3758 | MEDIUM | 6.1 | 1.8% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cros... |
| CVE-2020-3719 | HIGH | 7.5 | 3.2% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql inject... |
| CVE-2020-3718 | CRITICAL | 9.8 | 7.5% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security by... |
| CVE-2020-3717 | MEDIUM | 5.3 | 3.2% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traver... |
| CVE-2020-3716 | CRITICAL | 9.8 | 14.0% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserializa... |
| CVE-2020-3715 | MEDIUM | 6.1 | 1.8% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cros... |
| CVE-2020-3714 | HIGH | 7.8 | 3.6% | Jan 29, 2020 | Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea... |
| CVE-2020-3713 | HIGH | 7.8 | 3.6% | Jan 29, 2020 | Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea... |
| CVE-2020-3712 | HIGH | 7.8 | 3.5% | Jan 29, 2020 | Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea... |
| CVE-2020-3711 | HIGH | 7.8 | 3.5% | Jan 29, 2020 | Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea... |
| CVE-2020-3710 | HIGH | 7.8 | 3.6% | Jan 29, 2020 | Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea... |
| CVE-2020-8416 | HIGH | 7.5 | 14.2% | Jan 29, 2020 | IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to th... |
| CVE-2020-7247 | CRITICAL | 9.8 | 99.0% | Jan 29, 2020 | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to ... |
| CVE-2020-2108 | HIGH | 7.6 | 0.9% | Jan 29, 2020 | Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can b... |
| CVE-2020-2107 | MEDIUM | 4.3 | 0.6% | Jan 29, 2020 | Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenk... |
| CVE-2020-2106 | MEDIUM | 5.4 | 0.7% | Jan 29, 2020 | Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view,... |
| CVE-2020-2105 | MEDIUM | 5.4 | 1.8% | Jan 29, 2020 | REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks. |
| CVE-2020-2104 | MEDIUM | 4.3 | 1.1% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage cha... |
| CVE-2020-2103 | MEDIUM | 5.4 | 7.0% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI d... |
| CVE-2020-2102 | MEDIUM | 5.3 | 1.4% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC. |
| CVE-2020-2101 | MEDIUM | 5.3 | 1.4% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connec... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now