2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-26112HIGH7.5The email quota cache in cPanel before 90.0.10 allows overwriting of files.
CVE-2020-26109HIGH7.5cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).
CVE-2020-26107HIGH7.5cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
CVE-2020-26106HIGH7.5cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
CVE-2020-26104HIGH7.5In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
CVE-2020-26103HIGH7.5In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
CVE-2020-26102HIGH7.5In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
CVE-2020-26099HIGH7.5cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
CVE-2020-25748HIGH8.1A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, ...
CVE-2020-24718HIGH8.2bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020...
CVE-2020-24692HIGH7.1The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts...
CVE-2020-24621HIGH8.8A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11...
CVE-2020-24593HIGH7.2Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and acces...
CVE-2020-23837HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attacke...
CVE-2020-13387HIGH7.5Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.
CVE-2020-12824HIGH7.5Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.
CVE-2020-17365HIGH7.8Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an aut...
CVE-2020-15843HIGH7.3ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folde...
CVE-2020-13991HIGH7.5vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.
CVE-2020-8333HIGH7.8A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStatio...
CVE-2020-15850HIGH7.8Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access t...
CVE-2020-19447HIGH7.5SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_file...
CVE-2020-3560HIGH8.6A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial o...
CVE-2020-3559HIGH8.6A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an ...
CVE-2020-3552HIGH7.4A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthentic...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now