2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25050HIGH7.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The CMC service allows attackers to ...
CVE-2020-2075HIGH7.5Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulksca...
CVE-2020-24354HIGH8.8Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell...
CVE-2020-7527HIGH7.8Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege ...
CVE-2020-7526HIGH8.8Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could ...
CVE-2020-7525HIGH7.5Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and...
CVE-2020-7524HIGH7.5Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial ...
CVE-2020-7523HIGH7.8Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification...
CVE-2020-24363HIGH8.8TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP...
CVE-2020-20625HIGH7.5Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated S...
CVE-2020-15687HIGH7.5Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious ...
CVE-2020-13593HIGH8.8The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R...
CVE-2020-11618HIGH7.8THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start ...
CVE-2020-25032HIGH7.5An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to...
CVE-2020-25031HIGH7.8checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 execu...
CVE-2020-8097HIGH7.8An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Sec...
CVE-2020-14352HIGH8A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to ...
CVE-2020-7712HIGH7.2This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
CVE-2020-24972HIGH8.8The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code ...
CVE-2020-24897HIGH8.9The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to...
CVE-2020-25019HIGH7.5jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verify...
CVE-2020-3566HIGH8.6A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow a...
CVE-2020-15159HIGH7.6baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be execut...
CVE-2020-15155HIGH7.3baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is req...
CVE-2020-15154HIGH7.3baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is req...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now