2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-8276MEDIUM5.5The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the times...
CVE-2020-8150MEDIUM4.1A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the in...
CVE-2020-8133MEDIUM5.3A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite...
CVE-2020-25655MEDIUM6.5An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct...
CVE-2020-24353MEDIUM6.1Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
CVE-2020-28351MEDIUM6.1The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r...
CVE-2020-28349MEDIUM6.5An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplin...
CVE-2020-24405MEDIUM4.3Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inve...
CVE-2020-24402MEDIUM4.9Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integratio...
CVE-2020-24401MEDIUM6.5Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can st...
CVE-2020-28168MEDIUM5.9Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass...
CVE-2020-3592MEDIUM6.5A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem...
CVE-2020-3591MEDIUM4.3A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated,...
CVE-2020-3590MEDIUM6.4A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated,...
CVE-2020-3587MEDIUM6.4A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated,...
CVE-2020-3579MEDIUM6.1A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, r...
CVE-2020-3551MEDIUM6.1A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2020-28327MEDIUM5.3A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 1...
CVE-2020-27129MEDIUM6.7A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local at...
CVE-2020-27128MEDIUM6.5A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote ...
CVE-2020-27123MEDIUM5.5A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c...
CVE-2020-27122MEDIUM6.7A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an aut...
CVE-2020-27121MEDIUM6.5A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could a...
CVE-2020-26086MEDIUM4.3A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow ...
CVE-2020-26084MEDIUM6.5A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now