2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7512 | CRITICAL | 9.8 | 1.4% | Jun 16, 2020 | A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (... |
| CVE-2020-7508 | CRITICAL | 9.8 | 1.4% | Jun 16, 2020 | A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware versi... |
| CVE-2020-7500 | CRITICAL | 9.8 | 1.9% | Jun 16, 2020 | A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.... |
| CVE-2020-7498 | CRITICAL | 9.8 | 1.4% | Jun 16, 2020 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions).... |
| CVE-2020-7497 | CRITICAL | 9.8 | 2.3% | Jun 16, 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStru... |
| CVE-2020-9296 | CRITICAL | 9.8 | 2.0% | Jun 16, 2020 | Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violatio... |
| CVE-2020-0235 | CRITICAL | 9.8 | 0.4% | Jun 16, 2020 | In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size... |
| CVE-2020-0232 | CRITICAL | 9.8 | 0.4% | Jun 16, 2020 | Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work wi... |
| CVE-2020-0223 | CRITICAL | 9.8 | 0.4% | Jun 16, 2020 | This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Androi... |
| CVE-2020-5754 | CRITICAL | 9.1 | 1.5% | Jun 15, 2020 | Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability ov... |
| CVE-2020-12019 | CRITICAL | 9.8 | 2.2% | Jun 15, 2020 | WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to re... |
| CVE-2020-12001 | CRITICAL | 9.8 | 11.5% | Jun 15, 2020 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio... |
| CVE-2020-11969 | CRITICAL | 9.8 | 4.1% | Jun 15, 2020 | If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter... |
| CVE-2020-14034 | CRITICAL | 9.8 | 2.3% | Jun 15, 2020 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c ha... |
| CVE-2020-14033 | CRITICAL | 9.8 | 1.9% | Jun 15, 2020 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plu... |
| CVE-2020-14054 | CRITICAL | 9.8 | 1.4% | Jun 15, 2020 | SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows r... |
| CVE-2020-14011 | CRITICAL | 9.8 | 29.5% | Jun 15, 2020 | Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin accoun... |
| CVE-2020-4469 | CRITICAL | 9.8 | 13.4% | Jun 15, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. B... |
| CVE-2020-4216 | CRITICAL | 9.8 | 1.6% | Jun 15, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key... |
| CVE-2020-0595 | CRITICAL | 9.8 | 3.4% | Jun 15, 2020 | Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.6... |
| CVE-2020-0594 | CRITICAL | 9.8 | 3.5% | Jun 15, 2020 | Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12... |
| CVE-2020-14080 | CRITICAL | 9.8 | 2.4% | Jun 15, 2020 | TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows... |
| CVE-2020-14067 | CRITICAL | 9.8 | 1.2% | Jun 15, 2020 | The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files with... |
| CVE-2020-13656 | CRITICAL | 9.8 | 2.1% | Jun 12, 2020 | In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an... |
| CVE-2020-9633 | CRITICAL | 9.8 | 7.6% | Jun 12, 2020 | Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now