2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-3377HIGH8.8A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticat...
CVE-2020-16164HIGH7.4An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypas...
CVE-2020-16162HIGH7.5An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL pr...
CVE-2020-15131HIGH7.5In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation o...
CVE-2020-15130HIGH7.5In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for t...
CVE-2020-7829HIGH7.8DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malform...
CVE-2020-7828HIGH7.8DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malform...
CVE-2020-7827HIGH7.8DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed sp...
CVE-2020-15957HIGH7.5An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). ...
CVE-2020-14162HIGH7.8An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core s...
CVE-2020-12620HIGH7.8Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection...
CVE-2020-8219HIGH7.2An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change t...
CVE-2020-8218HIGH7.2A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform...
CVE-2020-8206HIGH8.1An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users prim...
CVE-2020-4185HIGH7.5IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2020-10713HIGH8.2A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB veri...
CVE-2020-3701HIGH7.8Use after free issue while processing error notification from camx driver due to not properly releasing the sequence dat...
CVE-2020-3700HIGH7.5Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi dri...
CVE-2020-5610HIGH7.8Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service...
CVE-2020-16143HIGH7.8The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current...
CVE-2020-5763HIGH8.8Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated rem...
CVE-2020-5762HIGH7.5Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-...
CVE-2020-5761HIGH7.5Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in ...
CVE-2020-5760HIGH7.8Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Una...
CVE-2020-16118HIGH7.5In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now