2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12471 | CRITICAL | 9.8 | 2.8% | Apr 29, 2020 | MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGal... |
| CVE-2020-11020 | CRITICAL | 9.8 | 1.5% | Apr 29, 2020 | Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication ... |
| CVE-2020-3955 | CRITICAL | 9.3 | 1.3% | Apr 29, 2020 | ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize s... |
| CVE-2020-8481 | CRITICAL | 9.8 | 1.8% | Apr 29, 2020 | For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions... |
| CVE-2020-8479 | CRITICAL | 9.8 | 2.2% | Apr 29, 2020 | For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions ... |
| CVE-2020-12443 | CRITICAL | 9.8 | 3.6% | Apr 29, 2020 | BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value ca... |
| CVE-2020-7452 | CRITICAL | 9.1 | 1.8% | Apr 29, 2020 | In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE... |
| CVE-2020-12442 | CRITICAL | 9.8 | 2.3% | Apr 28, 2020 | Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250. |
| CVE-2020-12429 | CRITICAL | 9.8 | 2.4% | Apr 28, 2020 | Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and aut... |
| CVE-2020-1745 | CRITICAL | 9.8 | 4.8% | Apr 28, 2020 | A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in U... |
| CVE-2020-12284 | CRITICAL | 9.8 | 3.8% | Apr 28, 2020 | cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MA... |
| CVE-2020-7640 | CRITICAL | 9.8 | 2.1% | Apr 27, 2020 | pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be con... |
| CVE-2020-7609 | CRITICAL | 9.8 | 1.6% | Apr 27, 2020 | node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fr... |
| CVE-2020-9294 | CRITICAL | 9.8 | 77.8% | Apr 27, 2020 | An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an... |
| CVE-2020-1952 | CRITICAL | 9.8 | 2.7% | Apr 27, 2020 | An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed ... |
| CVE-2020-12279 | CRITICAL | 9.8 | 5.1% | Apr 27, 2020 | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that... |
| CVE-2020-12278 | CRITICAL | 9.8 | 5.1% | Apr 27, 2020 | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exi... |
| CVE-2020-9068 | CRITICAL | 9.8 | 1.1% | Apr 27, 2020 | Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200... |
| CVE-2020-12133 | CRITICAL | 9.8 | 9.9% | Apr 27, 2020 | The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of... |
| CVE-2020-11817 | CRITICAL | 9.8 | 2.0% | Apr 27, 2020 | In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As... |
| CVE-2020-12274 | CRITICAL | 9.8 | 1.2% | Apr 27, 2020 | In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on ... |
| CVE-2020-12271 | CRITICAL | 9.8 | 43.1% | Apr 27, 2020 | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as e... |
| CVE-2020-12268 | CRITICAL | 9.8 | 2.6% | Apr 27, 2020 | jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow. |
| CVE-2020-12267 | CRITICAL | 9.8 | 2.3% | Apr 27, 2020 | setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock. |
| CVE-2020-12265 | CRITICAL | 9.8 | 2.2% | Apr 26, 2020 | The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now