2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10547 | CRITICAL | 9.8 | 36.1% | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by defa... |
| CVE-2020-10546 | CRITICAL | 9.8 | 87.3% | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, n... |
| CVE-2020-11094 | CRITICAL | 9.8 | 1.0% | Jun 4, 2020 | The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all informat... |
| CVE-2020-6493 | CRITICAL | 9.6 | 1.7% | Jun 3, 2020 | Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised... |
| CVE-2020-3258 | CRITICAL | 9.8 | 4.6% | Jun 3, 2020 | Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ... |
| CVE-2020-3227 | CRITICAL | 9.8 | 3.4% | Jun 3, 2020 | A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Softw... |
| CVE-2020-3198 | CRITICAL | 9.8 | 4.5% | Jun 3, 2020 | Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ... |
| CVE-2020-4177 | CRITICAL | 9.8 | 1.0% | Jun 3, 2020 | IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i... |
| CVE-2020-13756 | CRITICAL | 9.8 | 55.1% | Jun 3, 2020 | Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the... |
| CVE-2020-10516 | CRITICAL | 9.8 | 1.6% | Jun 3, 2020 | An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization... |
| CVE-2020-7115 | CRITICAL | 9.8 | 64.6% | Jun 3, 2020 | The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon succ... |
| CVE-2020-1963 | CRITICAL | 9.1 | 5.0% | Jun 3, 2020 | Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used ... |
| CVE-2020-12017 | CRITICAL | 9.8 | 2.3% | Jun 2, 2020 | GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerab... |
| CVE-2020-3641 | CRITICAL | 9.8 | 1.1% | Jun 2, 2020 | Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdra... |
| CVE-2020-3633 | CRITICAL | 9.8 | 1.1% | Jun 2, 2020 | Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allo... |
| CVE-2020-3615 | CRITICAL | 9.8 | 0.8% | Jun 2, 2020 | Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disas... |
| CVE-2020-8967 | CRITICAL | 9.8 | 1.0% | Jun 1, 2020 | There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php file... |
| CVE-2020-11844 | CRITICAL | 9.8 | 2.0% | May 29, 2020 | Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybri... |
| CVE-2020-12493 | CRITICAL | 10 | 1.4% | May 29, 2020 | An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the... |
| CVE-2020-13693 | CRITICAL | 9.8 | 43.9% | May 29, 2020 | An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi... |
| CVE-2020-11079 | CRITICAL | 9.8 | 2.6% | May 28, 2020 | node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote... |
| CVE-2020-7812 | CRITICAL | 9.8 | 0.7% | May 28, 2020 | Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allo... |
| CVE-2020-8606 | CRITICAL | 9.8 | 72.7% | May 27, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authent... |
| CVE-2020-11075 | CRITICAL | 9.9 | 1.8% | May 27, 2020 | In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to t... |
| CVE-2020-6831 | CRITICAL | 9.8 | 5.8% | May 26, 2020 | A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruptio... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now