2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8003 | MEDIUM | 5.5 | 0.3% | Jan 27, 2020 | A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of ser... |
| CVE-2020-8002 | MEDIUM | 5.5 | 0.3% | Jan 27, 2020 | A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of serv... |
| CVE-2020-8001 | CRITICAL | 9.8 | 1.6% | Jan 27, 2020 | The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account. |
| CVE-2020-8000 | CRITICAL | 9.8 | 2.4% | Jan 27, 2020 | Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account. |
| CVE-2020-7999 | CRITICAL | 9.8 | 1.3% | Jan 27, 2020 | The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY. |
| CVE-2020-7996 | MEDIUM | 6.1 | 1.2% | Jan 26, 2020 | htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header. |
| CVE-2020-7995 | CRITICAL | 9.8 | 4.5% | Jan 26, 2020 | The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attem... |
| CVE-2020-7994 | MEDIUM | 6.1 | 1.5% | Jan 26, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web sc... |
| CVE-2020-7991 | HIGH | 8.8 | 3.1% | Jan 26, 2020 | Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. |
| CVE-2020-7990 | MEDIUM | 6.1 | 0.9% | Jan 26, 2020 | Adive Framework 2.0.8 has admin/user/add userName XSS. |
| CVE-2020-7989 | MEDIUM | 6.1 | 0.9% | Jan 26, 2020 | Adive Framework 2.0.8 has admin/user/add userUsername XSS. |
| CVE-2020-7984 | HIGH | 7.5 | 2.5% | Jan 26, 2020 | SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain ad... |
| CVE-2020-3142 | HIGH | 7.5 | 1.5% | Jan 26, 2020 | A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated... |
| CVE-2020-3139 | MEDIUM | 5.3 | 1.0% | Jan 26, 2020 | A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Inf... |
| CVE-2020-3136 | MEDIUM | 6.1 | 0.8% | Jan 26, 2020 | A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attac... |
| CVE-2020-3134 | MEDIUM | 6.5 | 1.1% | Jan 26, 2020 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could... |
| CVE-2020-3131 | MEDIUM | 6.5 | 2.2% | Jan 26, 2020 | A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the c... |
| CVE-2020-3129 | MEDIUM | 4.8 | 0.6% | Jan 26, 2020 | A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, r... |
| CVE-2020-3121 | MEDIUM | 6.1 | 1.1% | Jan 26, 2020 | A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an ... |
| CVE-2020-3115 | HIGH | 8.8 | 0.3% | Jan 26, 2020 | A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to... |
| CVE-2020-7981 | CRITICAL | 9.8 | 1.5% | Jan 25, 2020 | sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with ... |
| CVE-2020-7980 | CRITICAL | 9.8 | 83.0% | Jan 25, 2020 | Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th... |
| CVE-2020-7596 | HIGH | 8.8 | 1.9% | Jan 25, 2020 | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. |
| CVE-2020-5226 | MEDIUM | 5.4 | 0.5% | Jan 24, 2020 | Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be su... |
| CVE-2020-5225 | MEDIUM | 5.4 | 0.6% | Jan 24, 2020 | Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and se... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now