2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-8580HIGH7.5SANtricity OS Controller Software versions 11.30 and higher are susceptible to a vulnerability which allows an unauthent...
CVE-2020-7198HIGH8.8There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synerg...
CVE-2020-27589HIGH7.5Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certa...
CVE-2020-27196HIGH7.5An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly par...
CVE-2020-26883HIGH7.5In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of craf...
CVE-2020-26882HIGH7.5In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON...
CVE-2020-10292HIGH8.2Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove ...
CVE-2020-10291HIGH7.5Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove ...
CVE-2020-28196HIGH7.5MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerbero...
CVE-2020-26521HIGH7.5The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
CVE-2020-5649HIGH7.5Resource management error vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT...
CVE-2020-5646HIGH7.5NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT...
CVE-2020-5645HIGH7.5Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBD...
CVE-2020-27347HIGH7.8In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-o...
CVE-2020-15708HIGH7.8Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker c...
CVE-2020-6877HIGH8.8A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the a...
CVE-2020-25837HIGH7.5Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerabil...
CVE-2020-25661HIGH8.8A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled ...
CVE-2020-13537HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8...
CVE-2020-13536HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8...
CVE-2020-5946HIGH7.5In BIG-IP Advanced WAF and FPS versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, under some circumstances,...
CVE-2020-5945HIGH8.4In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross ...
CVE-2020-5942HIGH7.5In BIG-IP PEM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-1...
CVE-2020-5941HIGH7.5On BIG-IP versions 16.0.0-16.0.0.1 and 15.1.0-15.1.0.5, using the RESOLV::lookup command within an iRule may cause the T...
CVE-2020-5939HIGH7.5In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.3, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, and 13.1.0-13.1.3.4, BIG-IP Virtual Edit...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now