2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6116HIGH7.8An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.1...
CVE-2020-6115HIGH7.8An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro...
CVE-2020-6113HIGH7.8An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13...
CVE-2020-6112HIGH7.8An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc....
CVE-2020-13948HIGH8.8While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests v...
CVE-2020-24373HIGH8.8A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
CVE-2020-16233HIGH7.5An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packe...
CVE-2020-14519HIGH7.5This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are a...
CVE-2020-14515HIGH7.5CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in ...
CVE-2020-14513HIGH7.5CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted licen...
CVE-2020-6781HIGH7.4Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17...
CVE-2020-6146HIGH8.8An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.3...
CVE-2020-13259HIGH8.8A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauth...
CVE-2020-10718HIGH7.5A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed ...
CVE-2020-25040HIGH8.8Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit contain...
CVE-2020-25039HIGH8.1Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namesp...
CVE-2020-14306HIGH8.8An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions thr...
CVE-2020-7532HIGH7.8A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and pri...
CVE-2020-7531HIGH7.8A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allow...
CVE-2020-7530HIGH8.8A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows...
CVE-2020-7528HIGH7.8A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) w...
CVE-2020-4409HIGH8.2IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbin...
CVE-2020-1748HIGH7.5A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityMan...
CVE-2020-10758HIGH7.5A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneous...
CVE-2020-24889HIGH7.8A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now