2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-8273HIGH8.8Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8...
CVE-2020-8272HIGH7.5Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1...
CVE-2020-8270HIGH8.8An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD version...
CVE-2020-8269HIGH8.8An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, ...
CVE-2020-8259HIGH8.1Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the...
CVE-2020-5666HIGH7.5Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '...
CVE-2020-2492HIGH7.2If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue...
CVE-2020-2490HIGH7.2If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue...
CVE-2020-25695HIGH8.8A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9...
CVE-2020-25694HIGH8.1A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9...
CVE-2020-28268HIGH7.5Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial o...
CVE-2020-15481HIGH7.8An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 B...
CVE-2020-5796HIGH7.8Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the...
CVE-2020-27217HIGH7.5In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received fro...
CVE-2020-12313HIGH8.8Insufficient control flow management in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an u...
CVE-2020-8583HIGH7.5Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could a...
CVE-2020-6019HIGH7.5Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConn...
CVE-2020-26222HIGH8.8Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Jav...
CVE-2020-25557HIGH8.8In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. A...
CVE-2020-25538HIGH8.8An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and r...
CVE-2020-25165HIGH7.5BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The ...
CVE-2020-25155HIGH7.5The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information...
CVE-2020-25151HIGH7.5The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack...
CVE-2020-21667HIGH7.2In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malic...
CVE-2020-6156HIGH7.8A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now