2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8899 | CRITICAL | 9.8 | 5.7% | May 6, 2020 | There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q... |
| CVE-2020-3318 | CRITICAL | 9.8 | 1.0% | May 6, 2020 | Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software cou... |
| CVE-2020-3187 | CRITICAL | 9.1 | 96.6% | May 6, 2020 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th... |
| CVE-2020-3125 | CRITICAL | 9.8 | 2.4% | May 6, 2020 | A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow a... |
| CVE-2020-7806 | CRITICAL | 9.8 | 0.7% | May 6, 2020 | Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supporte... |
| CVE-2020-11035 | CRITICAL | 9.3 | 0.8% | May 5, 2020 | In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The im... |
| CVE-2020-10634 | CRITICAL | 9.1 | 1.4% | May 5, 2020 | SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file s... |
| CVE-2020-12641 | CRITICAL | 9.8 | 84.5% | May 4, 2020 | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in... |
| CVE-2020-12640 | CRITICAL | 9.8 | 6.7% | May 4, 2020 | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plu... |
| CVE-2020-8790 | CRITICAL | 9.8 | 1.7% | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combi... |
| CVE-2020-12110 | CRITICAL | 9.8 | 14.4% | May 4, 2020 | Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304,... |
| CVE-2020-1961 | CRITICAL | 9.8 | 4.6% | May 4, 2020 | Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1... |
| CVE-2020-1959 | CRITICAL | 9.8 | 4.8% | May 4, 2020 | A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary ... |
| CVE-2020-1631 | CRITICAL | 9.8 | 4.7% | May 4, 2020 | A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication... |
| CVE-2020-12627 | CRITICAL | 9.8 | 1.4% | May 4, 2020 | Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key. |
| CVE-2020-7645 | CRITICAL | 9.8 | 1.0% | May 2, 2020 | All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in ... |
| CVE-2020-10683 | CRITICAL | 9.8 | 7.3% | May 1, 2020 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE ... |
| CVE-2020-5887 | CRITICAL | 9.1 | 1.8% | Apr 30, 2020 | On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism fo... |
| CVE-2020-5886 | CRITICAL | 9.1 | 0.8% | Apr 30, 2020 | On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection ... |
| CVE-2020-5885 | CRITICAL | 9.1 | 0.8% | Apr 30, 2020 | On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection... |
| CVE-2020-5884 | CRITICAL | 9.1 | 1.5% | Apr 30, 2020 | On versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.4, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the default deploym... |
| CVE-2020-7136 | CRITICAL | 9.8 | 79.5% | Apr 30, 2020 | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access... |
| CVE-2020-11015 | CRITICAL | 9.1 | 0.7% | Apr 30, 2020 | A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC add... |
| CVE-2020-11651 | CRITICAL | 9.8 | 96.4% | Apr 30, 2020 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla... |
| CVE-2020-11942 | CRITICAL | 9.8 | 1.2% | Apr 29, 2020 | An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now