2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-3403HIGH7.8A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to ...
CVE-2020-3400HIGH8.8A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize ...
CVE-2020-3399HIGH8.6A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE S...
CVE-2020-3396HIGH7.2A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allo...
CVE-2020-3393HIGH7.8A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attack...
CVE-2020-3390HIGH7.4A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wi...
CVE-2020-3359HIGH8.6A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Con...
CVE-2020-3141HIGH8.8Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote a...
CVE-2020-15223HIGH8In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationH...
CVE-2020-15222HIGH8.1In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_k...
CVE-2020-13119HIGH8.1ismartgate PRO 1.5.9 is vulnerable to clickjacking.
CVE-2020-12837HIGH7.5ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magi...
CVE-2020-12282HIGH8.8iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible ...
CVE-2020-24365HIGH8.8An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic n...
CVE-2020-12817HIGH8.8An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticat...
CVE-2020-16148HIGH7.2The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell...
CVE-2020-24560HIGH7.5An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o...
CVE-2020-15604HIGH7.5An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o...
CVE-2020-25603HIGH7.8An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event chan...
CVE-2020-25599HIGH7An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potenti...
CVE-2020-25595HIGH7.8An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen...
CVE-2020-11031HIGH7.5In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on th...
CVE-2020-24213HIGH7.5An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memor...
CVE-2020-2284HIGH7.1Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE)...
CVE-2020-2280HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execu...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now