2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3377 | HIGH | 8.8 | 1.0% | Jul 31, 2020 | A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticat... |
| CVE-2020-16164 | HIGH | 7.4 | 0.9% | Jul 30, 2020 | An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypas... |
| CVE-2020-16162 | HIGH | 7.5 | 0.7% | Jul 30, 2020 | An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL pr... |
| CVE-2020-15131 | HIGH | 7.5 | 1.0% | Jul 30, 2020 | In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation o... |
| CVE-2020-15130 | HIGH | 7.5 | 1.0% | Jul 30, 2020 | In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for t... |
| CVE-2020-7829 | HIGH | 7.8 | 1.2% | Jul 30, 2020 | DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malform... |
| CVE-2020-7828 | HIGH | 7.8 | 1.2% | Jul 30, 2020 | DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malform... |
| CVE-2020-7827 | HIGH | 7.8 | 1.3% | Jul 30, 2020 | DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed sp... |
| CVE-2020-15957 | HIGH | 7.5 | 1.6% | Jul 30, 2020 | An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). ... |
| CVE-2020-14162 | HIGH | 7.8 | 0.6% | Jul 30, 2020 | An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core s... |
| CVE-2020-12620 | HIGH | 7.8 | 1.5% | Jul 30, 2020 | Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection... |
| CVE-2020-8219 | HIGH | 7.2 | 2.2% | Jul 30, 2020 | An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change t... |
| CVE-2020-8218 | HIGH | 7.2 | 32.7% | Jul 30, 2020 | A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform... |
| CVE-2020-8206 | HIGH | 8.1 | 3.0% | Jul 30, 2020 | An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users prim... |
| CVE-2020-4185 | HIGH | 7.5 | 0.8% | Jul 30, 2020 | IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attack... |
| CVE-2020-10713 | HIGH | 8.2 | 1.1% | Jul 30, 2020 | A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB veri... |
| CVE-2020-3701 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Use after free issue while processing error notification from camx driver due to not properly releasing the sequence dat... |
| CVE-2020-3700 | HIGH | 7.5 | 1.1% | Jul 30, 2020 | Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi dri... |
| CVE-2020-5610 | HIGH | 7.8 | 1.4% | Jul 30, 2020 | Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service... |
| CVE-2020-16143 | HIGH | 7.8 | 0.4% | Jul 29, 2020 | The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current... |
| CVE-2020-5763 | HIGH | 8.8 | 2.7% | Jul 29, 2020 | Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated rem... |
| CVE-2020-5762 | HIGH | 7.5 | 3.4% | Jul 29, 2020 | Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-... |
| CVE-2020-5761 | HIGH | 7.5 | 4.1% | Jul 29, 2020 | Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in ... |
| CVE-2020-5760 | HIGH | 7.8 | 5.5% | Jul 29, 2020 | Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Una... |
| CVE-2020-16118 | HIGH | 7.5 | 2.1% | Jul 29, 2020 | In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now