2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9278 | CRITICAL | 9.1 | 1.6% | Apr 20, 2020 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by... |
| CVE-2020-9277 | CRITICAL | 9.8 | 2.5% | Apr 20, 2020 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modul... |
| CVE-2020-9275 | CRITICAL | 9.8 | 1.7% | Apr 20, 2020 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote... |
| CVE-2020-11928 | CRITICAL | 9.8 | 3.6% | Apr 20, 2020 | In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta... |
| CVE-2020-11895 | CRITICAL | 9.1 | 1.7% | Apr 19, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c. |
| CVE-2020-11894 | CRITICAL | 9.1 | 1.7% | Apr 19, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c. |
| CVE-2020-0073 | CRITICAL | 9.8 | 1.3% | Apr 17, 2020 | In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check... |
| CVE-2020-0072 | CRITICAL | 9.8 | 1.3% | Apr 17, 2020 | In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check... |
| CVE-2020-0071 | CRITICAL | 9.8 | 1.3% | Apr 17, 2020 | In rw_t2t_extract_default_locks_info of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds ... |
| CVE-2020-0070 | CRITICAL | 9.8 | 1.3% | Apr 17, 2020 | In rw_t2t_update_lock_attributes of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds chec... |
| CVE-2020-11878 | CRITICAL | 9.8 | 1.3% | Apr 17, 2020 | The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) fo... |
| CVE-2020-11873 | CRITICAL | 9.8 | 0.4% | Apr 17, 2020 | An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer ove... |
| CVE-2020-10377 | CRITICAL | 9.8 | 0.5% | Apr 17, 2020 | A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated att... |
| CVE-2020-10211 | CRITICAL | 9.8 | 3.0% | Apr 17, 2020 | A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthent... |
| CVE-2020-7485 | CRITICAL | 9.8 | 1.8% | Apr 16, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier c... |
| CVE-2020-7224 | CRITICAL | 9.8 | 2.3% | Apr 16, 2020 | The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered... |
| CVE-2020-7114 | CRITICAL | 9.8 | 1.1% | Apr 16, 2020 | A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, ... |
| CVE-2020-1964 | CRITICAL | 9.8 | 4.8% | Apr 16, 2020 | It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not ... |
| CVE-2020-11820 | CRITICAL | 9.8 | 1.8% | Apr 16, 2020 | Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the entities_id parameter... |
| CVE-2020-11819 | CRITICAL | 9.8 | 26.8% | Apr 16, 2020 | In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve... |
| CVE-2020-11816 | CRITICAL | 9.8 | 1.8% | Apr 16, 2020 | Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) par... |
| CVE-2020-11815 | CRITICAL | 9.8 | 2.3% | Apr 16, 2020 | In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a re... |
| CVE-2020-11812 | CRITICAL | 9.8 | 1.7% | Apr 16, 2020 | Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the filters[0][value] or ... |
| CVE-2020-11811 | CRITICAL | 9.8 | 3.0% | Apr 16, 2020 | In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability w... |
| CVE-2020-3653 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from users... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now