2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-15238HIGH7Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-me...
CVE-2020-7755HIGH7.5All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted ...
CVE-2020-11858HIGH7.8Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Br...
CVE-2020-7754HIGH7.5This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer ...
CVE-2020-23945HIGH7.5A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter...
CVE-2020-8579HIGH7.5Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access ...
CVE-2020-6023HIGH7.8Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in...
CVE-2020-23864HIGH7.8An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a mali...
CVE-2020-7753HIGH7.5All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
CVE-2020-27180HIGH7.5konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
CVE-2020-15352HIGH7.2An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) befo...
CVE-2020-1915HIGH7.5An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c7...
CVE-2020-26878HIGH8.8Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (...
CVE-2020-26566HIGH7.5A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a ...
CVE-2020-15271HIGH8.8In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and ...
CVE-2020-7752HIGH8.8This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker...
CVE-2020-27187HIGH7.8An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic...
CVE-2020-7125HIGH8.8A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
CVE-2020-24632HIGH7.2A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1....
CVE-2020-24631HIGH7.2A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3...
CVE-2020-15897HIGH7.5Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attack...
CVE-2020-13100HIGH7.5Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x bef...
CVE-2020-7751HIGH7.2pathval before version 1.1.1 is vulnerable to prototype pollution.
CVE-2020-24848HIGH7.8FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform ...
CVE-2020-5990HIGH7.8NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which m...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now