2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7133 | CRITICAL | 9.8 | 1.7% | Apr 24, 2020 | A unauthorized remote access vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. |
| CVE-2020-7131 | CRITICAL | 9 | 1.1% | Apr 24, 2020 | This document describes a security vulnerability in Blade Maintenance Entity, Integrated Maintenance Entity and Maintena... |
| CVE-2020-6826 | CRITICAL | 9.8 | 1.2% | Apr 24, 2020 | Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some ... |
| CVE-2020-6825 | CRITICAL | 9.8 | 1.9% | Apr 24, 2020 | Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox... |
| CVE-2020-6823 | CRITICAL | 9.8 | 1.6% | Apr 24, 2020 | A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, a... |
| CVE-2020-5869 | CRITICAL | 9.1 | 0.5% | Apr 24, 2020 | In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to re... |
| CVE-2020-5868 | CRITICAL | 9.8 | 2.2% | Apr 24, 2020 | In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell c... |
| CVE-2020-12134 | CRITICAL | 9.8 | 1.3% | Apr 24, 2020 | Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log. |
| CVE-2020-4415 | CRITICAL | 9.8 | 8.1% | Apr 23, 2020 | IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checki... |
| CVE-2020-11945 | CRITICAL | 9.8 | 27.2% | Apr 23, 2020 | An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gai... |
| CVE-2020-11939 | CRITICAL | 9.8 | 3.3% | Apr 23, 2020 | In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlle... |
| CVE-2020-12079 | CRITICAL | 10 | 2.2% | Apr 23, 2020 | Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron con... |
| CVE-2020-10915 | CRITICAL | 9.8 | 86.6% | Apr 22, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.... |
| CVE-2020-10914 | CRITICAL | 9.8 | 47.0% | Apr 22, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.... |
| CVE-2020-7489 | CRITICAL | 9.8 | 1.5% | Apr 22, 2020 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerabili... |
| CVE-2020-7487 | CRITICAL | 9.8 | 0.7% | Apr 22, 2020 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute... |
| CVE-2020-7055 | CRITICAL | 9.9 | 3.1% | Apr 22, 2020 | An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function... |
| CVE-2020-11796 | CRITICAL | 9.8 | 1.2% | Apr 22, 2020 | In JetBrains Space through 2020-04-22, the password authentication implementation was insecure. |
| CVE-2020-11690 | CRITICAL | 9.8 | 2.2% | Apr 22, 2020 | In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases. |
| CVE-2020-10569 | CRITICAL | 9.8 | 3.2% | Apr 21, 2020 | SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additiona... |
| CVE-2020-11967 | CRITICAL | 9.8 | 3.2% | Apr 21, 2020 | In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of ... |
| CVE-2020-11966 | CRITICAL | 9.8 | 3.0% | Apr 21, 2020 | In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root p... |
| CVE-2020-11965 | CRITICAL | 9.8 | 2.0% | Apr 21, 2020 | In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access vi... |
| CVE-2020-11963 | CRITICAL | 9.8 | 3.1% | Apr 21, 2020 | IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because o... |
| CVE-2020-9279 | CRITICAL | 9.8 | 2.2% | Apr 20, 2020 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now