2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-13543HIGH8.8A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web...
CVE-2020-13542HIGH7.8A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depend...
CVE-2020-13531HIGH8.8A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specia...
CVE-2020-2324HIGH7.5Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2322HIGH7.5Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attac...
CVE-2020-2321HIGH8.1A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to s...
CVE-2020-28939HIGH7.2OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability al...
CVE-2020-28937HIGH7.5OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to acce...
CVE-2020-6021HIGH7.8Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which t...
CVE-2020-6111HIGH7.5An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Program...
CVE-2020-5680HIGH7.5Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a den...
CVE-2020-5676HIGH7.5GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vec...
CVE-2020-13493HIGH7.8A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f...
CVE-2020-25638HIGH7.4A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementatio...
CVE-2020-12524HIGH7.5Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W ...
CVE-2020-29458HIGH8.8Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
CVE-2020-5423HIGH7.5CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticat...
CVE-2020-27813HIGH7.5An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An att...
CVE-2020-14305HIGH8.1An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functiona...
CVE-2020-8539HIGH7.8Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an atta...
CVE-2020-28993HIGH7.5A Directory Traversal vulnerability exists in ATX miniCMTS200a Broadband Gateway through 2.0 and Pico CMTS through 2.0. ...
CVE-2020-7547HIGH8.8A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA So...
CVE-2020-7545HIGH7.2A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Sof...
CVE-2020-25181HIGH8.8WECON PLC Editor Versions 1.3.8 and prior has a heap-based buffer overflow vulnerabilities have been identified that may...
CVE-2020-25177HIGH8.8WECON PLC Editor Versions 1.3.8 and prior has a stack-based buffer overflow vulnerability has been identified that may a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now