2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-7460HIGH7In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 1...
CVE-2020-13365HIGH8.8Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocu...
CVE-2020-13364HIGH8.8A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, ...
CVE-2020-7361HIGH8.8The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' co...
CVE-2020-7352HIGH8.8The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to th...
CVE-2020-17366HIGH7.4An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended acce...
CVE-2020-7298HIGH8.4Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real tim...
CVE-2020-15127HIGH7.5In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, ...
CVE-2020-13404HIGH8.8The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
CVE-2020-15113HIGH7.1In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory pa...
CVE-2020-4481HIGH8.2IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE...
CVE-2020-16253HIGH8.1The PgHero gem through 2.6.0 for Ruby allows CSRF.
CVE-2020-15135HIGH7.6save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Token...
CVE-2020-15956HIGH7.5ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer...
CVE-2020-15943HIGH8.1An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possibl...
CVE-2020-13522HIGH7.1An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially craf...
CVE-2020-16203HIGH7.8Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited ...
CVE-2020-16199HIGH7.8Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulne...
CVE-2020-16134HIGH8An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet...
CVE-2020-7823HIGH7.8DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandle...
CVE-2020-7822HIGH7.8DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishand...
CVE-2020-6012HIGH7.4ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sop...
CVE-2020-15467HIGH8.8The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticat...
CVE-2020-5617HIGH7.8Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unaut...
CVE-2020-5615HIGH8.8Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now