2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6870HIGH8The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit t...
CVE-2020-3969HIGH7.8VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), ...
CVE-2020-14017HIGH7.5An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are ...
CVE-2020-14015HIGH7.5An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation cod...
CVE-2020-13700HIGH7.5An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object r...
CVE-2020-13443HIGH8.8ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose...
CVE-2020-14005HIGH8.8Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to ex...
CVE-2020-15014HIGH8.8pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.
CVE-2020-12865HIGH8A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network a...
CVE-2020-12861HIGH8.8A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as t...
CVE-2020-7667HIGH7.5In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanit...
CVE-2020-10280HIGH7.5The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, eff...
CVE-2020-10274HIGH7.1The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default...
CVE-2020-10273HIGH7.5MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual proper...
CVE-2020-12033HIGH8.8In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not ...
CVE-2020-5367HIGH8.1Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p...
CVE-2020-14978HIGH8.1An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can co...
CVE-2020-14977HIGH8.1An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, ...
CVE-2020-14975HIGH7.8The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code ...
CVE-2020-14974HIGH7.1The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running a...
CVE-2020-13155HIGH8.8clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.p...
CVE-2020-7668HIGH7.5In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in z...
CVE-2020-7664HIGH7.5In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in ...
CVE-2020-11068HIGH8.8In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. ...
CVE-2020-14971HIGH7.8Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now