2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-3354MEDIUM4.8A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent...
CVE-2020-3350MEDIUM6.3A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, loc...
CVE-2020-3347MEDIUM5.5A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain acc...
CVE-2020-3337MEDIUM6.1A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user t...
CVE-2020-3245MEDIUM5.3A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthentica...
CVE-2020-3244MEDIUM5.3A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Route...
CVE-2020-3242MEDIUM4.9A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative ...
CVE-2020-3241MEDIUM6.5A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perfor...
CVE-2020-3236MEDIUM6.7A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local a...
CVE-2020-8619MEDIUM4.9In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edi...
CVE-2020-8618MEDIUM4.9An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger t...
CVE-2020-14408MEDIUM6.1An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login rou...
CVE-2020-4532MEDIUM5.3IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8....
CVE-2020-7932MEDIUM5.7OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query paramet...
CVE-2020-14405MEDIUM6.5An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
CVE-2020-14404MEDIUM5.4An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
CVE-2020-14403MEDIUM5.4An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
CVE-2020-14402MEDIUM5.4An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
CVE-2020-14401MEDIUM6.5An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
CVE-2020-11914MEDIUM4.3The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.
CVE-2020-11913MEDIUM5.3The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
CVE-2020-11912MEDIUM5.3The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.
CVE-2020-11911MEDIUM5.3The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.
CVE-2020-11910MEDIUM5.3The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.
CVE-2020-11909MEDIUM5.3The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now