2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8180 | CRITICAL | 9.9 | 1.7% | Jun 8, 2020 | A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk co... |
| CVE-2020-6109 | CRITICAL | 9.8 | 4.9% | Jun 8, 2020 | An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including anima... |
| CVE-2020-13910 | CRITICAL | 9.1 | 1.2% | Jun 7, 2020 | Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an in... |
| CVE-2020-13909 | CRITICAL | 9.8 | 1.5% | Jun 7, 2020 | The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x ser... |
| CVE-2020-10071 | CRITICAL | 9.8 | 3.4% | Jun 5, 2020 | The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer o... |
| CVE-2020-10070 | CRITICAL | 9.8 | 2.9% | Jun 5, 2020 | In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execu... |
| CVE-2020-10062 | CRITICAL | 9.8 | 2.9% | Jun 5, 2020 | An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote... |
| CVE-2020-4450 | CRITICAL | 9.8 | 33.9% | Jun 5, 2020 | IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the ... |
| CVE-2020-4448 | CRITICAL | 9.8 | 12.2% | Jun 5, 2020 | IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbi... |
| CVE-2020-11975 | CRITICAL | 9.8 | 29.9% | Jun 5, 2020 | Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the J... |
| CVE-2020-13841 | CRITICAL | 9.8 | 0.7% | Jun 5, 2020 | An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attac... |
| CVE-2020-13840 | CRITICAL | 9.8 | 0.7% | Jun 5, 2020 | An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can... |
| CVE-2020-13839 | CRITICAL | 9.8 | 0.9% | Jun 5, 2020 | An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can... |
| CVE-2020-13768 | CRITICAL | 9.8 | 2.1% | Jun 4, 2020 | In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to a... |
| CVE-2020-13835 | CRITICAL | 9.8 | 0.4% | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a ... |
| CVE-2020-13833 | CRITICAL | 9.1 | 0.5% | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbi... |
| CVE-2020-13832 | CRITICAL | 9.8 | 0.7% | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software. The Widevine ... |
| CVE-2020-13831 | CRITICAL | 9.8 | 0.4% | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic ... |
| CVE-2020-13814 | CRITICAL | 9.8 | 1.7% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a... |
| CVE-2020-13805 | CRITICAL | 9.8 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the C... |
| CVE-2020-13804 | CRITICAL | 9.8 | 1.6% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded use... |
| CVE-2020-4193 | CRITICAL | 9.8 | 1.4% | Jun 4, 2020 | IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force ... |
| CVE-2020-9292 | CRITICAL | 9.8 | 1.5% | Jun 4, 2020 | An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated p... |
| CVE-2020-10549 | CRITICAL | 9.8 | 36.2% | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' pass... |
| CVE-2020-10548 | CRITICAL | 9.8 | 36.1% | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passw... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now