2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7818 | HIGH | 7.8 | 1.2% | Jul 17, 2020 | DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF fil... |
| CVE-2020-10605 | HIGH | 7.5 | 1.1% | Jul 17, 2020 | Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files. |
| CVE-2020-5758 | HIGH | 8.8 | 4.4% | Jul 17, 2020 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authe... |
| CVE-2020-5756 | HIGH | 8.8 | 2.5% | Jul 17, 2020 | Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab ... |
| CVE-2020-15110 | HIGH | 8.1 | 0.9% | Jul 17, 2020 | In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant ... |
| CVE-2020-15108 | HIGH | 7.1 | 1.2% | Jul 17, 2020 | In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1. |
| CVE-2020-0228 | HIGH | 7.5 | 0.4% | Jul 17, 2020 | There is an improper configuration of recorder related service. Product: AndroidVersions: Android SoCAndroid ID: A-15633... |
| CVE-2020-0227 | HIGH | 7.8 | 0.3% | Jul 17, 2020 | In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission c... |
| CVE-2020-0226 | HIGH | 7.8 | 0.3% | Jul 17, 2020 | In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead... |
| CVE-2020-15816 | HIGH | 8.8 | 3.5% | Jul 17, 2020 | In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could p... |
| CVE-2020-0120 | HIGH | 7.8 | 0.2% | Jul 17, 2020 | In notifyErrorForPendingRequests of QCamera3HWI.cpp, there is a possible out of bounds write due to a heap buffer overfl... |
| CVE-2020-1653 | HIGH | 7.5 | 1.6% | Jul 17, 2020 | On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which ... |
| CVE-2020-1650 | HIGH | 7.5 | 1.0% | Jul 17, 2020 | On Juniper Networks Junos MX Series with service card configured, receipt of a stream of specific packets may crash the ... |
| CVE-2020-1649 | HIGH | 7.5 | 1.1% | Jul 17, 2020 | When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configur... |
| CVE-2020-1648 | HIGH | 7.5 | 1.3% | Jul 17, 2020 | On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing proces... |
| CVE-2020-1646 | HIGH | 7.5 | 1.0% | Jul 17, 2020 | On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a r... |
| CVE-2020-1645 | HIGH | 8.3 | 0.6% | Jul 17, 2020 | When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-M... |
| CVE-2020-1644 | HIGH | 7.5 | 1.3% | Jul 17, 2020 | On Juniper Networks Junos OS and Junos OS Evolved devices, the receipt of a specific BGP UPDATE packet causes an interna... |
| CVE-2020-1640 | HIGH | 7.5 | 1.4% | Jul 17, 2020 | An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (rout... |
| CVE-2020-15813 | HIGH | 8.1 | 0.8% | Jul 17, 2020 | Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database... |
| CVE-2020-5131 | HIGH | 7.8 | 0.5% | Jul 17, 2020 | SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite... |
| CVE-2020-4464 | HIGH | 8.8 | 13.2% | Jul 17, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary c... |
| CVE-2020-9688 | HIGH | 7.8 | 4.8% | Jul 17, 2020 | Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to a... |
| CVE-2020-9673 | HIGH | 7.8 | 1.0% | Jul 17, 2020 | Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll searc... |
| CVE-2020-9672 | HIGH | 7.8 | 1.0% | Jul 17, 2020 | Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll searc... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now