2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6013HIGH8.8ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the ...
CVE-2020-5372HIGH7.5Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to externa...
CVE-2020-5371HIGH8.8Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulner...
CVE-2020-5368HIGH7.5Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated ...
CVE-2020-5352HIGH8.8Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated...
CVE-2020-14303HIGH7.5A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba...
CVE-2020-15466HIGH7.5In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/pa...
CVE-2020-15530HIGH7.8An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM p...
CVE-2020-15529HIGH7.8An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a g...
CVE-2020-15528HIGH7.8An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or un...
CVE-2020-15523HIGH7.8In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan hors...
CVE-2020-7284HIGH7.8Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to ga...
CVE-2020-10281HIGH7.5This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access ...
CVE-2020-7283HIGH8.8Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edi...
CVE-2020-15518HIGH8.8VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, w...
CVE-2020-8188HIGH8.8We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and U...
CVE-2020-8163HIGH8.8The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the...
CVE-2020-8161HIGH8.6A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerabi...
CVE-2020-15082HIGH8.8In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variable...
CVE-2020-2211HIGH8.8Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the ins...
CVE-2020-12119HIGH8.1Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value ...
CVE-2020-15503HIGH7.5LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_im...
CVE-2020-5911HIGH7.3In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packag...
CVE-2020-5910HIGH7.5In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use ...
CVE-2020-15502HIGH7.5The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web site...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now