2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3928 | CRITICAL | 9.8 | 0.9% | Jun 12, 2020 | GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in a... |
| CVE-2020-13702 | CRITICAL | 10 | 2.2% | Jun 11, 2020 | The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables atta... |
| CVE-2020-0217 | CRITICAL | 9.8 | 0.8% | Jun 11, 2020 | In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could l... |
| CVE-2020-0201 | CRITICAL | 9.8 | 1.8% | Jun 11, 2020 | In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This co... |
| CVE-2020-0138 | CRITICAL | 9.8 | 1.4% | Jun 11, 2020 | In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could... |
| CVE-2020-4101 | CRITICAL | 9.8 | 1.1% | Jun 11, 2020 | "HCL Digital Experience is susceptible to Server Side Request Forgery." |
| CVE-2020-13854 | CRITICAL | 9.8 | 3.0% | Jun 11, 2020 | Artica Pandora FMS 7.44 allows privilege escalation. |
| CVE-2020-13901 | CRITICAL | 9.8 | 2.6% | Jun 10, 2020 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-... |
| CVE-2020-4043 | CRITICAL | 9.8 | 2.6% | Jun 10, 2020 | phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading ... |
| CVE-2020-12757 | CRITICAL | 9.8 | 1.5% | Jun 10, 2020 | HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly gener... |
| CVE-2020-0117 | CRITICAL | 9.8 | 1.6% | Jun 10, 2020 | In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remot... |
| CVE-2020-7589 | CRITICAL | 9.1 | 2.0% | Jun 10, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead t... |
| CVE-2020-7675 | CRITICAL | 9.8 | 2.5% | Jun 10, 2020 | cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument execu... |
| CVE-2020-7674 | CRITICAL | 9.8 | 2.5% | Jun 10, 2020 | access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is... |
| CVE-2020-7673 | CRITICAL | 9.8 | 2.5% | Jun 10, 2020 | node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend`... |
| CVE-2020-6275 | CRITICAL | 9.8 | 1.4% | Jun 10, 2020 | SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Serv... |
| CVE-2020-6263 | CRITICAL | 9.8 | 1.4% | Jun 10, 2020 | Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10,... |
| CVE-2020-6265 | CRITICAL | 9.8 | 1.4% | Jun 9, 2020 | SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an... |
| CVE-2020-9850 | CRITICAL | 9.8 | 77.2% | Jun 9, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa... |
| CVE-2020-9838 | CRITICAL | 9.8 | 2.5% | Jun 9, 2020 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5. A re... |
| CVE-2020-9412 | CRITICAL | 9.8 | 2.3% | Jun 9, 2020 | The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vu... |
| CVE-2020-9411 | CRITICAL | 9.8 | 1.4% | Jun 9, 2020 | The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vu... |
| CVE-2020-13160 | CRITICAL | 9.8 | 80.6% | Jun 9, 2020 | AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut... |
| CVE-2020-12800 | CRITICAL | 9.8 | 78.8% | Jun 8, 2020 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa... |
| CVE-2020-9099 | CRITICAL | 9.8 | 0.9% | Jun 8, 2020 | Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now