2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13092 | CRITICAL | 9.8 | 2.6% | May 15, 2020 | scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to ... |
| CVE-2020-13091 | CRITICAL | 9.8 | 3.4% | May 15, 2020 | pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() fun... |
| CVE-2020-12889 | CRITICAL | 9.8 | 1.2% | May 15, 2020 | MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case. |
| CVE-2020-12651 | CRITICAL | 9.8 | 6.6% | May 15, 2020 | SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow b... |
| CVE-2020-12834 | CRITICAL | 9.8 | 11.1% | May 15, 2020 | eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSO... |
| CVE-2020-10620 | CRITICAL | 9.8 | 1.2% | May 14, 2020 | Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an at... |
| CVE-2020-10612 | CRITICAL | 9.1 | 1.1% | May 14, 2020 | Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. Ho... |
| CVE-2020-0221 | CRITICAL | 9.8 | 0.5% | May 14, 2020 | Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation... |
| CVE-2020-0103 | CRITICAL | 9.8 | 1.6% | May 14, 2020 | In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This coul... |
| CVE-2020-12874 | CRITICAL | 9.8 | 0.9% | May 14, 2020 | Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication ... |
| CVE-2020-11973 | CRITICAL | 9.8 | 6.6% | May 14, 2020 | Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1... |
| CVE-2020-11972 | CRITICAL | 9.8 | 5.5% | May 14, 2020 | Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to ... |
| CVE-2020-11066 | CRITICAL | 10 | 1.5% | May 14, 2020 | In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.... |
| CVE-2020-2018 | CRITICAL | 9 | 1.3% | May 13, 2020 | An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access ... |
| CVE-2020-2001 | CRITICAL | 9.8 | 1.3% | May 13, 2020 | An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that ... |
| CVE-2020-12832 | CRITICAL | 9.8 | 7.1% | May 13, 2020 | WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files be... |
| CVE-2020-9502 | CRITICAL | 9.8 | 1.7% | May 13, 2020 | Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user... |
| CVE-2020-7454 | CRITICAL | 9.8 | 2.7% | May 13, 2020 | In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3... |
| CVE-2020-12763 | CRITICAL | 9.8 | 3.4% | May 13, 2020 | TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow i... |
| CVE-2020-10654 | CRITICAL | 9.8 | 3.5% | May 13, 2020 | Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be... |
| CVE-2020-6242 | CRITICAL | 9.8 | 0.8% | May 12, 2020 | SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an att... |
| CVE-2020-12823 | CRITICAL | 9.8 | 4.6% | May 12, 2020 | OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other im... |
| CVE-2020-1939 | CRITICAL | 9.8 | 2.5% | May 12, 2020 | The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional co... |
| CVE-2020-8159 | CRITICAL | 9.8 | 5.3% | May 12, 2020 | There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a w... |
| CVE-2020-10022 | CRITICAL | 9.8 | 2.3% | May 11, 2020 | A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now