2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6881 | HIGH | 7.5 | 0.6% | Dec 21, 2020 | ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to ver... |
| CVE-2020-5808 | HIGH | 7.5 | 1.1% | Dec 21, 2020 | In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan ... |
| CVE-2020-4870 | HIGH | 7.5 | 1.7% | Dec 21, 2020 | IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications... |
| CVE-2020-27254 | HIGH | 7.5 | 1.3% | Dec 21, 2020 | Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products a... |
| CVE-2020-26263 | HIGH | 7.5 | 1.3% | Dec 21, 2020 | tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before ve... |
| CVE-2020-17526 | HIGH | 7.7 | 23.3% | Dec 21, 2020 | Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a maliciou... |
| CVE-2020-35273 | HIGH | 8 | 0.6% | Dec 21, 2020 | EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to ... |
| CVE-2020-35579 | HIGH | 7.5 | 1.1% | Dec 20, 2020 | tindy2013 subconverter 0.6.4 has a /sub?target=%TARGET%&url=%URL%&config=%CONFIG% API endpoint that accepts an arbitrary... |
| CVE-2020-35573 | HIGH | 7.5 | 2.7% | Dec 20, 2020 | srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timesta... |
| CVE-2020-7201 | HIGH | 8.8 | 0.6% | Dec 18, 2020 | A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G... |
| CVE-2020-5803 | HIGH | 8.1 | 1.7% | Dec 18, 2020 | Relative Path Traversal in Marvell QConvergeConsole GUI 5.5.0.74 allows a remote, authenticated attacker to delete arbit... |
| CVE-2020-27781 | HIGH | 7.1 | 0.3% | Dec 18, 2020 | User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential pr... |
| CVE-2020-13535 | HIGH | 7.8 | 0.7% | Dec 18, 2020 | A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker ca... |
| CVE-2020-13519 | HIGH | 8.8 | 0.6% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A ... |
| CVE-2020-13515 | HIGH | 8.8 | 0.5% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A ... |
| CVE-2020-13514 | HIGH | 8.8 | 0.5% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA... |
| CVE-2020-13513 | HIGH | 8.8 | 0.5% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA... |
| CVE-2020-13512 | HIGH | 8.8 | 0.5% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA... |
| CVE-2020-27687 | HIGH | 8.8 | 1.5% | Dec 18, 2020 | ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send... |
| CVE-2020-26280 | HIGH | 8.9 | 1.1% | Dec 18, 2020 | OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and electi... |
| CVE-2020-20299 | HIGH | 7.5 | 1.5% | Dec 18, 2020 | WeiPHP 5.0 does not properly restrict access to pages, related to using POST. |
| CVE-2020-26174 | HIGH | 8.8 | 1.2% | Dec 18, 2020 | tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the... |
| CVE-2020-35555 | HIGH | 7.8 | 0.1% | Dec 18, 2020 | An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configuration is supported,... |
| CVE-2020-35554 | HIGH | 7.8 | 0.1% | Dec 18, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There is a WebView SSL erro... |
| CVE-2020-35553 | HIGH | 7.5 | 0.4% | Dec 18, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Qualcomm SM8250 chipsets) software. They all... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now