2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10064CRITICAL9.8Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buff...
CVE-2020-9452HIGH7.8An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to qua...
CVE-2020-9451MEDIUM5.5An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where...
CVE-2020-9450HIGH7.8An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can b...
CVE-2020-20178HIGH7.5Ethereum 0xe933c0cd9784414d5f278c114904f5a84b396919#code.sol latest version is affected by a denial of service vulnerabi...
CVE-2020-26560HIGH8.1Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authe...
CVE-2020-26559HIGH8.8Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the...
CVE-2020-26558MEDIUM4.2Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-mi...
CVE-2020-26557HIGH7.5Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the Auth...
CVE-2020-26556HIGH7.5Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful b...
CVE-2020-26555MEDIUM5.4Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated ...
CVE-2020-21041HIGH7.5Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a r...
CVE-2020-20907CRITICAL9.1MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/syst...
CVE-2020-4990HIGH8.8IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements...
CVE-2020-28911MEDIUM6.5Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwor...
CVE-2020-28910CRITICAL9.8Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalati...
CVE-2020-28909HIGH8.8Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification o...
CVE-2020-28908CRITICAL9.8Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.
CVE-2020-28907CRITICAL9.8Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Exec...
CVE-2020-28906HIGH8.8Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escal...
CVE-2020-28905HIGH8.8Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via...
CVE-2020-28904CRITICAL9.8Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via i...
CVE-2020-28903MEDIUM6.1Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server t...
CVE-2020-28902CRITICAL9.8Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
CVE-2020-28901CRITICAL9.8Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vecto...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now