2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-9769CRITICAL9.8Multiple issues were addressed by updating to version 8.1.1850. This issue is fixed in macOS Catalina 10.15.4. Multiple ...
CVE-2020-3911CRITICAL9.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Ca...
CVE-2020-3910CRITICAL9.8A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Ca...
CVE-2020-3909CRITICAL9.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Ca...
CVE-2020-10867CRITICAL9.8An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi...
CVE-2020-11455CRITICAL9.8LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM...
CVE-2020-7947CRITICAL9.8An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain...
CVE-2020-5344CRITICAL9.8Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer ove...
CVE-2020-6008CRITICAL9.8LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution
CVE-2020-4208CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key...
CVE-2020-10595CRITICAL9.8pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental pr...
CVE-2020-7611CRITICAL9.8All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable...
CVE-2020-11105CRITICAL9.8An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw po...
CVE-2020-10374CRITICAL9.8A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command exe...
CVE-2020-5723CRITICAL9.8The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta...
CVE-2020-7610CRITICAL9.8All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknow...
CVE-2020-10956CRITICAL9.8GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
CVE-2020-3936CRITICAL9.8UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, ...
CVE-2020-10993CRITICAL9.1Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java.
CVE-2020-10992CRITICAL9.8Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.
CVE-2020-10991CRITICAL9.8Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
CVE-2020-10990CRITICAL9.8An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.j...
CVE-2020-10828CRITICAL9.8A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote ...
CVE-2020-10827CRITICAL9.8A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote ...
CVE-2020-10826CRITICAL9.8/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to ach...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now