2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-10837CRITICAL9.8An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet ...
CVE-2020-10836CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The Widev...
CVE-2020-10835CRITICAL9.8An issue was discovered on Samsung mobile devices with any (before February 2020 for Exynos modem chipsets) software. Th...
CVE-2020-6972CRITICAL9.1In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by...
CVE-2020-10938CRITICAL9.8GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in m...
CVE-2020-1747CRITICAL9.8A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code...
CVE-2020-1944CRITICAL9.8There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling at...
CVE-2020-10879CRITICAL9.8rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nod...
CVE-2020-8868CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve ...
CVE-2020-6967CRITICAL9.8In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platfor...
CVE-2020-7480CRITICAL9.8A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versi...
CVE-2020-5722CRITICAL9.8The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte...
CVE-2020-7475CRITICAL9.8A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective...
CVE-2020-9760CRITICAL9.8An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with...
CVE-2020-10661CRITICAL9.1HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing neste...
CVE-2020-9752CRITICAL9.8Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system...
CVE-2020-10806CRITICAL9.8eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 20...
CVE-2020-10799CRITICAL9.8The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
CVE-2020-8137CRITICAL9.8Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be contr...
CVE-2020-8135CRITICAL9.8The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attack...
CVE-2020-7961CRITICAL9.8Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c...
CVE-2020-9423CRITICAL9.8LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of ...
CVE-2020-10674CRITICAL9.8PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argumen...
CVE-2020-3922CRITICAL9.8LisoMail, by ArmorX, allows SQL Injections, attackers can access the database without authentication via a URL parameter...
CVE-2020-8600CRITICAL9.8Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now