2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-7818HIGH7.8DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF fil...
CVE-2020-10605HIGH7.5Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.
CVE-2020-5758HIGH8.8Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authe...
CVE-2020-5756HIGH8.8Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab ...
CVE-2020-15110HIGH8.1In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant ...
CVE-2020-15108HIGH7.1In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
CVE-2020-0228HIGH7.5There is an improper configuration of recorder related service. Product: AndroidVersions: Android SoCAndroid ID: A-15633...
CVE-2020-0227HIGH7.8In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission c...
CVE-2020-0226HIGH7.8In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead...
CVE-2020-15816HIGH8.8In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could p...
CVE-2020-0120HIGH7.8In notifyErrorForPendingRequests of QCamera3HWI.cpp, there is a possible out of bounds write due to a heap buffer overfl...
CVE-2020-1653HIGH7.5On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which ...
CVE-2020-1650HIGH7.5On Juniper Networks Junos MX Series with service card configured, receipt of a stream of specific packets may crash the ...
CVE-2020-1649HIGH7.5When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configur...
CVE-2020-1648HIGH7.5On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing proces...
CVE-2020-1646HIGH7.5On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a r...
CVE-2020-1645HIGH8.3When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-M...
CVE-2020-1644HIGH7.5On Juniper Networks Junos OS and Junos OS Evolved devices, the receipt of a specific BGP UPDATE packet causes an interna...
CVE-2020-1640HIGH7.5An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (rout...
CVE-2020-15813HIGH8.1Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database...
CVE-2020-5131HIGH7.8SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite...
CVE-2020-4464HIGH8.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary c...
CVE-2020-9688HIGH7.8Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to a...
CVE-2020-9673HIGH7.8Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll searc...
CVE-2020-9672HIGH7.8Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll searc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now