2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12753 | CRITICAL | 9.8 | 2.5% | May 11, 2020 | An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution... |
| CVE-2020-12747 | CRITICAL | 9.8 | 0.4% | May 11, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 chipsets) software. Th... |
| CVE-2020-12746 | CRITICAL | 9.8 | 1.1% | May 11, 2020 | An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) (Exynos chipsets) software. Attackers... |
| CVE-2020-12743 | CRITICAL | 9.8 | 1.5% | May 11, 2020 | An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent u... |
| CVE-2020-12766 | CRITICAL | 9.8 | 1.0% | May 9, 2020 | Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter. |
| CVE-2020-12761 | CRITICAL | 9.1 | 1.6% | May 9, 2020 | modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-... |
| CVE-2020-12637 | CRITICAL | 9.8 | 0.7% | May 9, 2020 | Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled duri... |
| CVE-2020-11532 | CRITICAL | 9.8 | 77.5% | May 8, 2020 | Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode... |
| CVE-2020-11530 | CRITICAL | 9.8 | 95.7% | May 8, 2020 | A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in ... |
| CVE-2020-12740 | CRITICAL | 9.1 | 1.7% | May 8, 2020 | tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being tri... |
| CVE-2020-12022 | CRITICAL | 9.8 | 1.7% | May 8, 2020 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could... |
| CVE-2020-12006 | CRITICAL | 9.8 | 3.7% | May 8, 2020 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist... |
| CVE-2020-12002 | CRITICAL | 9.8 | 9.1% | May 8, 2020 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities e... |
| CVE-2020-10638 | CRITICAL | 9.8 | 7.1% | May 8, 2020 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities ex... |
| CVE-2020-12735 | CRITICAL | 9.8 | 1.7% | May 8, 2020 | reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover. |
| CVE-2020-12720 | CRITICAL | 9.8 | 88.9% | May 8, 2020 | vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. |
| CVE-2020-11052 | CRITICAL | 9.8 | 1.6% | May 7, 2020 | In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute... |
| CVE-2020-10794 | CRITICAL | 9.8 | 1.4% | May 7, 2020 | Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the appl... |
| CVE-2020-10176 | CRITICAL | 9.8 | 2.3% | May 7, 2020 | ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands. |
| CVE-2020-4429 | CRITICAL | 9.8 | 71.4% | May 7, 2020 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ... |
| CVE-2020-4428 | CRITICAL | 9.1 | 61.7% | May 7, 2020 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary co... |
| CVE-2020-4427 | CRITICAL | 9.8 | 70.0% | May 7, 2020 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest... |
| CVE-2020-7805 | CRITICAL | 9.8 | 2.6% | May 7, 2020 | An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This i... |
| CVE-2020-7646 | CRITICAL | 9.8 | 1.9% | May 7, 2020 | curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input. |
| CVE-2020-11431 | CRITICAL | 9.1 | 2.1% | May 7, 2020 | The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remot... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now