2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25866HIGH7.5In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a bu...
CVE-2020-25863HIGH7.5In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was ad...
CVE-2020-25862HIGH7.5In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in ...
CVE-2020-25803HIGH7.2Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2020-8781HIGH7.8Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-pri...
CVE-2020-7466HIGH7.5The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication m...
CVE-2020-25802HIGH7.2Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2020-25644HIGH7.5A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It m...
CVE-2020-25643HIGH7.2A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read ove...
CVE-2020-24219HIGH7.5An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthentic...
CVE-2020-24216HIGH7.5An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrato...
CVE-2020-15598HIGH7.5Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Tr...
CVE-2020-25987HIGH7.5MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is b...
CVE-2020-25613HIGH7.5An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP serv...
CVE-2020-5634HIGH8.8ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-17...
CVE-2020-5632HIGH7.8InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revisi...
CVE-2020-15235HIGH7.5In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would norm...
CVE-2020-26048HIGH8.8The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within...
CVE-2020-15236HIGH7.5In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with...
CVE-2020-8182HIGH8Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permiss...
CVE-2020-26061HIGH7.5ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerabili...
CVE-2020-12302HIGH7.8Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user...
CVE-2020-25636HIGH7.1A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file t...
CVE-2020-7709HIGH7.2This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
CVE-2020-25776HIGH7.8Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an atta...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now