2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-16244HIGH7.2GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible t...
CVE-2020-7122HIGH7.5Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been ...
CVE-2020-7121HIGH7.5Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been ...
CVE-2020-24625HIGH7.5Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE P...
CVE-2020-24624HIGH7.5Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE...
CVE-2020-14365HIGH7.1A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, wh...
CVE-2020-10714HIGH7.5A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with...
CVE-2020-25826HIGH7.8PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSub...
CVE-2020-25821HIGH7.5peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability onl...
CVE-2020-3569HIGH8.6Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software coul...
CVE-2020-3143HIGH7.2A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TeleP...
CVE-2020-3135HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unaut...
CVE-2020-3133HIGH7.5A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a...
CVE-2020-25515HIGH7.8Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<s...
CVE-2020-25514HIGH8.4Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://...
CVE-2020-14031HIGH7.2An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be u...
CVE-2020-14028HIGH7.2An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Auto...
CVE-2020-14026HIGH8.8CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS ...
CVE-2020-14025HIGH8.8Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a lin...
CVE-2020-14022HIGH8.8Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contac...
CVE-2020-25487HIGH7.8PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php...
CVE-2020-16202HIGH7.8WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, whic...
CVE-2020-4622HIGH7.5IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it us...
CVE-2020-4621HIGH8.8IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due t...
CVE-2020-4620HIGH8.8IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now