2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2801 | CRITICAL | 9.8 | 2.6% | Apr 15, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th... |
| CVE-2020-2791 | CRITICAL | 9.8 | 2.1% | Apr 15, 2020 | Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported ve... |
| CVE-2020-2733 | CRITICAL | 9.8 | 18.6% | Apr 15, 2020 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics)... |
| CVE-2020-10511 | CRITICAL | 9.8 | 2.2% | Apr 15, 2020 | HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure ... |
| CVE-2020-10507 | CRITICAL | 9.8 | 1.2% | Apr 15, 2020 | The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted ... |
| CVE-2020-10505 | CRITICAL | 9.8 | 1.1% | Apr 15, 2020 | The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection... |
| CVE-2020-6195 | CRITICAL | 9.8 | 0.6% | Apr 14, 2020 | SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, l... |
| CVE-2020-6238 | CRITICAL | 9.3 | 1.3% | Apr 14, 2020 | SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xy... |
| CVE-2020-10383 | CRITICAL | 9.8 | 1.8% | Apr 14, 2020 | An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. The... |
| CVE-2020-11673 | CRITICAL | 9.8 | 3.5% | Apr 13, 2020 | An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipul... |
| CVE-2020-11722 | CRITICAL | 9.8 | 3.9% | Apr 12, 2020 | Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytec... |
| CVE-2020-11710 | CRITICAL | 9.8 | 33.8% | Apr 12, 2020 | An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces othe... |
| CVE-2020-11708 | CRITICAL | 9.8 | 1.6% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetU... |
| CVE-2020-11705 | CRITICAL | 9.8 | 0.9% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to loa... |
| CVE-2020-3952 | CRITICAL | 9.8 | 90.4% | Apr 10, 2020 | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi... |
| CVE-2020-8961 | CRITICAL | 9.8 | 2.0% | Apr 9, 2020 | An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a w... |
| CVE-2020-10631 | CRITICAL | 9.8 | 1.5% | Apr 9, 2020 | An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0... |
| CVE-2020-10625 | CRITICAL | 9.8 | 1.6% | Apr 9, 2020 | WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account. |
| CVE-2020-10619 | CRITICAL | 9.1 | 14.3% | Apr 9, 2020 | An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) cont... |
| CVE-2020-10621 | CRITICAL | 9.8 | 1.6% | Apr 9, 2020 | Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2). |
| CVE-2020-11656 | CRITICAL | 9.8 | 7.4% | Apr 9, 2020 | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause tha... |
| CVE-2020-1615 | CRITICAL | 9.8 | 1.7% | Apr 8, 2020 | The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without ... |
| CVE-2020-1614 | CRITICAL | 10 | 1.4% | Apr 8, 2020 | A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) in... |
| CVE-2020-1992 | CRITICAL | 9.8 | 3.4% | Apr 8, 2020 | A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC)... |
| CVE-2020-10980 | CRITICAL | 9.8 | 1.8% | Apr 8, 2020 | GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now