2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-15147HIGH8.5Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exp...
CVE-2020-24057HIGH8.8The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows th...
CVE-2020-24056HIGH7.5A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31,...
CVE-2020-24053HIGH7.5Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidential...
CVE-2020-15309HIGH7An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a ca...
CVE-2020-12457HIGH7.5An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for...
CVE-2020-5774HIGH7.1Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios...
CVE-2020-15070HIGH8.8Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres...
CVE-2020-14215HIGH7.5Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrato...
CVE-2020-24574HIGH7.8The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local pri...
CVE-2020-24571HIGH7.5NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
CVE-2020-24567HIGH7.8voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file...
CVE-2020-24359HIGH7.5HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet i...
CVE-2020-16282HIGH8.8In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged...
CVE-2020-16281HIGH7.8The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restri...
CVE-2020-10289HIGH8.8Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YA...
CVE-2020-8870HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8869HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-15862HIGH7.8Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability ...
CVE-2020-15861HIGH7.8Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
CVE-2020-15638HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.2...
CVE-2020-15635HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-15630HIGH7.8This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P...
CVE-2020-15629HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-15531HIGH8.8Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remot...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now