2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0606 | HIGH | 8.8 | 17.3% | Jan 14, 2020 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi... |
| CVE-2020-0605 | HIGH | 8.8 | 17.9% | Jan 14, 2020 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi... |
| CVE-2020-0603 | HIGH | 8.8 | 20.0% | Jan 14, 2020 | A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memor... |
| CVE-2020-0602 | HIGH | 7.5 | 7.6% | Jan 14, 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of ... |
| CVE-2020-0601 | HIGH | 8.1 | 89.4% | Jan 14, 2020 | A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c... |
| CVE-2020-7057 | MEDIUM | 5.3 | 1.1% | Jan 14, 2020 | Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessio... |
| CVE-2020-7054 | HIGH | 8.8 | 1.1% | Jan 14, 2020 | MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer ov... |
| CVE-2020-7053 | HIGH | 7.8 | 0.6% | Jan 14, 2020 | In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a us... |
| CVE-2020-6173 | MEDIUM | 5.3 | 1.4% | Jan 14, 2020 | TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption. |
| CVE-2020-5509 | HIGH | 7.2 | 5.8% | Jan 14, 2020 | PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile ima... |
| CVE-2020-5505 | CRITICAL | 9.8 | 44.3% | Jan 14, 2020 | Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction... |
| CVE-2020-5180 | HIGH | 7.8 | 0.4% | Jan 14, 2020 | Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be use... |
| CVE-2020-6307 | MEDIUM | 4.3 | 0.7% | Jan 14, 2020 | Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) doe... |
| CVE-2020-6306 | LOW | 2.7 | 0.6% | Jan 14, 2020 | Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.... |
| CVE-2020-6305 | MEDIUM | 6.1 | 0.7% | Jan 14, 2020 | PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode u... |
| CVE-2020-6304 | HIGH | 7.5 | 1.3% | Jan 14, 2020 | Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21,... |
| CVE-2020-6303 | MEDIUM | 5.4 | 0.5% | Jan 14, 2020 | SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to C... |
| CVE-2020-5193 | MEDIUM | 6.1 | 0.9% | Jan 14, 2020 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata... |
| CVE-2020-5853 | MEDIUM | 5.4 | 0.5% | Jan 14, 2020 | In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.... |
| CVE-2020-5852 | HIGH | 7.5 | 1.2% | Jan 14, 2020 | Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Microkernel (TMM). Thi... |
| CVE-2020-5851 | MEDIUM | 4.6 | 0.3% | Jan 14, 2020 | On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications ... |
| CVE-2020-5196 | HIGH | 8.1 | 1.2% | Jan 14, 2020 | Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create f... |
| CVE-2020-5194 | MEDIUM | 5.4 | 0.7% | Jan 14, 2020 | The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip fun... |
| CVE-2020-6958 | CRITICAL | 9.1 | 2.4% | Jan 14, 2020 | An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other p... |
| CVE-2020-6955 | MEDIUM | 6.1 | 0.7% | Jan 13, 2020 | An issue was discovered on Cayin SMP-PRO4 devices. They allow image_preview.html?filename= reflected XSS. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now