2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-10050HIGH7.8A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service ...
CVE-2020-10049HIGH7.3A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts fo...
CVE-2020-15163HIGH8.2Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously do...
CVE-2020-13127HIGH8.8A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.04.1 allows remote authenticated attackers to...
CVE-2020-2042HIGH7.2A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt sy...
CVE-2020-2041HIGH7.5An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to ...
CVE-2020-2038HIGH7.2An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to exe...
CVE-2020-2037HIGH7.2An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to exe...
CVE-2020-2036HIGH8.8A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker ab...
CVE-2020-25212HIGH7A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt me...
CVE-2020-24566HIGH7.5In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment o...
CVE-2020-1749HIGH7.5A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tu...
CVE-2020-14384HIGH7.5A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBos...
CVE-2020-6320HIGH8.1SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are rest...
CVE-2020-6318HIGH7.2A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (>...
CVE-2020-6302HIGH8.1SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is...
CVE-2020-14342HIGH7It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to...
CVE-2020-7325HIGH7.8Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files wh...
CVE-2020-7320HIGH7.3Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 ...
CVE-2020-7319HIGH8.8Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Updat...
CVE-2020-3656HIGH7.8Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI...
CVE-2020-3617HIGH7.1u'Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing ...
CVE-2020-11135HIGH7.5u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer ...
CVE-2020-11129HIGH7.8u'During the error occurrence in capture request, the buffer is freed and later accessed causing the camera APP to fail ...
CVE-2020-11124HIGH7.8u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max clien...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now