2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-3530HIGH8.4A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate...
CVE-2020-3495HIGH8.8A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The...
CVE-2020-3478HIGH8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, re...
CVE-2020-3473HIGH7.8A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate...
CVE-2020-3430HIGH8.8A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated...
CVE-2020-24941HIGH7.5An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some sit...
CVE-2020-24940HIGH7.5An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in...
CVE-2020-24999HIGH7.8There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by send...
CVE-2020-24996HIGH7.8There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can ...
CVE-2020-1894HIGH8.8A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, Whats...
CVE-2020-1890HIGH7.5A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 coul...
CVE-2020-1886HIGH8.8A buffer overflow in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could hav...
CVE-2020-25125HIGH7.8GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other imp...
CVE-2020-11579HIGH7.5An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation ...
CVE-2020-24162HIGH7.8The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attack...
CVE-2020-24161HIGH7.8Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerabi...
CVE-2020-24160HIGH7.8Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers t...
CVE-2020-24159HIGH7.8NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissi...
CVE-2020-24158HIGH7.8360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute maliciou...
CVE-2020-23811HIGH7.5xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.jav...
CVE-2020-25068HIGH7.5Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unau...
CVE-2020-25042HIGH7.2An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authentic...
CVE-2020-24948HIGH7.2The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimat...
CVE-2020-7381HIGH7.8In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in t...
CVE-2020-4638HIGH7.2IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now