2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11604 | CRITICAL | 9.1 | 0.5% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. There is an ... |
| CVE-2020-11603 | CRITICAL | 9.8 | 0.8% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. Type confusi... |
| CVE-2020-11600 | CRITICAL | 9.8 | 0.8% | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) software. There is arbitrary code execution in the Finger... |
| CVE-2020-11630 | CRITICAL | 9.8 | 1.3% | Apr 8, 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification o... |
| CVE-2020-11543 | CRITICAL | 9.8 | 2.6% | Apr 8, 2020 | OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the... |
| CVE-2020-6974 | CRITICAL | 9.8 | 1.9% | Apr 7, 2020 | Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to b... |
| CVE-2020-11514 | CRITICAL | 9.8 | 9.1% | Apr 7, 2020 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPres... |
| CVE-2020-7614 | CRITICAL | 9.8 | 3.5% | Apr 7, 2020 | npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated t... |
| CVE-2020-11586 | CRITICAL | 9.8 | 1.2% | Apr 6, 2020 | An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API reque... |
| CVE-2020-11598 | CRITICAL | 9.8 | 2.5% | Apr 6, 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitr... |
| CVE-2020-11597 | CRITICAL | 9.8 | 1.5% | Apr 6, 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST req... |
| CVE-2020-11580 | CRITICAL | 9.1 | 1.1% | Apr 6, 2020 | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed ... |
| CVE-2020-11545 | CRITICAL | 9.8 | 1.6% | Apr 6, 2020 | Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email... |
| CVE-2020-7622 | CRITICAL | 9.8 | 1.6% | Apr 6, 2020 | This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set t... |
| CVE-2020-7636 | CRITICAL | 9.8 | 4.4% | Apr 6, 2020 | adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command fu... |
| CVE-2020-7635 | CRITICAL | 9.8 | 4.4% | Apr 6, 2020 | compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha optio... |
| CVE-2020-7634 | CRITICAL | 9.8 | 2.8% | Apr 6, 2020 | heroku-addonpool through 0.1.15 is vulnerable to Command Injection. |
| CVE-2020-7633 | CRITICAL | 9.8 | 4.4% | Apr 6, 2020 | apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via th... |
| CVE-2020-7632 | CRITICAL | 9.8 | 4.4% | Apr 6, 2020 | node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options arg... |
| CVE-2020-7631 | CRITICAL | 9.8 | 3.9% | Apr 6, 2020 | diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path arg... |
| CVE-2020-10265 | CRITICAL | 9.4 | 1.4% | Apr 6, 2020 | Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Versi... |
| CVE-2020-11558 | CRITICAL | 9.8 | 1.5% | Apr 5, 2020 | An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_c... |
| CVE-2020-11548 | CRITICAL | 9.8 | 5.2% | Apr 5, 2020 | The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. T... |
| CVE-2020-11542 | CRITICAL | 9.8 | 1.0% | Apr 4, 2020 | 3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication... |
| CVE-2020-11518 | CRITICAL | 9.8 | 18.8% | Apr 4, 2020 | Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now