2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13539 | HIGH | 7.8 | 0.6% | Jan 5, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V... |
| CVE-2020-4762 | HIGH | 8.8 | 1.3% | Jan 5, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow... |
| CVE-2020-35488 | HIGH | 7.5 | 7.6% | Jan 5, 2021 | The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of... |
| CVE-2020-17519 | HIGH | 7.5 | 97.9% | Jan 5, 2021 | A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file... |
| CVE-2020-17518 | HIGH | 7.5 | 52.3% | Jan 5, 2021 | Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the l... |
| CVE-2020-5361 | HIGH | 7.6 | 0.4% | Jan 4, 2021 | Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist... |
| CVE-2020-29491 | HIGH | 8.6 | 1.8% | Jan 4, 2021 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate... |
| CVE-2020-36156 | HIGH | 8.8 | 2.0% | Jan 4, 2021 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalatio... |
| CVE-2020-36154 | HIGH | 7.8 | 0.4% | Jan 4, 2021 | The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMD... |
| CVE-2020-25275 | HIGH | 7.5 | 4.7% | Jan 4, 2021 | Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafte... |
| CVE-2020-22550 | HIGH | 7.5 | 2.2% | Jan 4, 2021 | Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to do... |
| CVE-2020-4942 | HIGH | 8.8 | 0.5% | Jan 4, 2021 | IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an at... |
| CVE-2020-4917 | HIGH | 8.8 | 0.4% | Jan 4, 2021 | IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious ... |
| CVE-2020-4912 | HIGH | 7.2 | 1.1% | Jan 4, 2021 | IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when ... |
| CVE-2020-35965 | HIGH | 7.5 | 2.3% | Jan 4, 2021 | decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to... |
| CVE-2020-35963 | HIGH | 7.8 | 1.3% | Jan 3, 2021 | flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correc... |
| CVE-2020-35962 | HIGH | 7.5 | 1.3% | Jan 3, 2021 | The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum ... |
| CVE-2020-28852 | HIGH | 7.5 | 1.7% | Jan 2, 2021 | In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processi... |
| CVE-2020-28851 | HIGH | 7.5 | 2.3% | Jan 2, 2021 | In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- exten... |
| CVE-2020-35950 | HIGH | 8.8 | 0.9% | Jan 1, 2021 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almos... |
| CVE-2020-35948 | HIGH | 8.8 | 24.9% | Jan 1, 2021 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta... |
| CVE-2020-35947 | HIGH | 7.4 | 1.1% | Jan 1, 2021 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lack... |
| CVE-2020-35945 | HIGH | 8.8 | 2.4% | Jan 1, 2021 | An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authent... |
| CVE-2020-35944 | HIGH | 8.8 | 0.8% | Jan 1, 2021 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vuln... |
| CVE-2020-35939 | HIGH | 8.8 | 2.1% | Jan 1, 2021 | PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now