2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7543 | HIGH | 7.5 | 1.3% | Dec 11, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega... |
| CVE-2020-7542 | HIGH | 7.5 | 1.3% | Dec 11, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega... |
| CVE-2020-7539 | HIGH | 7.5 | 1.1% | Dec 11, 2020 | A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, L... |
| CVE-2020-7537 | HIGH | 7.5 | 1.4% | Dec 11, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega... |
| CVE-2020-7536 | HIGH | 7.5 | 1.1% | Dec 11, 2020 | A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versio... |
| CVE-2020-7535 | HIGH | 7.5 | 1.4% | Dec 11, 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerabilit... |
| CVE-2020-28219 | HIGH | 7.8 | 0.3% | Dec 11, 2020 | A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original rele... |
| CVE-2020-28217 | HIGH | 7.5 | 0.6% | Dec 11, 2020 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that woul... |
| CVE-2020-28216 | HIGH | 7.5 | 0.5% | Dec 11, 2020 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that woul... |
| CVE-2020-4829 | HIGH | 7.8 | 0.3% | Dec 10, 2020 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root ... |
| CVE-2020-26269 | HIGH | 7.5 | 0.7% | Dec 10, 2020 | In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing ... |
| CVE-2020-26267 | HIGH | 7.8 | 0.2% | Dec 10, 2020 | In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_form... |
| CVE-2020-25967 | HIGH | 8.8 | 1.3% | Dec 10, 2020 | The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vu... |
| CVE-2020-13526 | HIGH | 8.8 | 1.7% | Dec 10, 2020 | SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP r... |
| CVE-2020-12594 | HIGH | 7.2 | 1.5% | Dec 10, 2020 | A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the s... |
| CVE-2020-12516 | HIGH | 7.5 | 1.9% | Dec 10, 2020 | Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial ... |
| CVE-2020-17159 | HIGH | 7.8 | 3.1% | Dec 10, 2020 | Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability |
| CVE-2020-17158 | HIGH | 8.8 | 2.5% | Dec 10, 2020 | Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability |
| CVE-2020-17156 | HIGH | 7.8 | 2.6% | Dec 10, 2020 | Visual Studio Remote Code Execution Vulnerability |
| CVE-2020-17152 | HIGH | 8.8 | 2.5% | Dec 10, 2020 | Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability |
| CVE-2020-17150 | HIGH | 7.8 | 2.9% | Dec 10, 2020 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2020-17148 | HIGH | 7.8 | 3.6% | Dec 10, 2020 | Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability |
| CVE-2020-17147 | HIGH | 8.7 | 1.3% | Dec 10, 2020 | Dynamics CRM Webclient Cross-site Scripting Vulnerability |
| CVE-2020-17144 | HIGH | 8.4 | 36.5% | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability |
| CVE-2020-17143 | HIGH | 8.8 | 70.6% | Dec 10, 2020 | Microsoft Exchange Server Information Disclosure Vulnerability |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now