2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-7501HIGH8.8A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vij...
CVE-2020-7496HIGH7.8A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pa...
CVE-2020-7494HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStru...
CVE-2020-7493HIGH7.8A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in E...
CVE-2020-13162HIGH7A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down ...
CVE-2020-14195HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-8543HIGH7.5OX App Suite through 7.10.3 has Improper Input Validation.
CVE-2020-4310HIGH7.5IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to a...
CVE-2020-0234HIGH7.8In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. T...
CVE-2020-13431HIGH7.8I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions o...
CVE-2020-5358HIGH7.8Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escala...
CVE-2020-14163HIGH7.5An issue was discovered in ecma/operations/ecma-container-object.c in JerryScript 2.2.0. Operations with key/value pairs...
CVE-2020-5755HIGH7.8Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against ren...
CVE-2020-5742HIGH8.8Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin applicatio...
CVE-2020-12005HIGH7.5FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio...
CVE-2020-12003HIGH7.5FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio...
CVE-2020-11999HIGH8.1FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio...
CVE-2020-14159HIGH8.8By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands a...
CVE-2020-13651HIGH7.8An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It all...
CVE-2020-13650HIGH7.5An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to ...
CVE-2020-14156HIGH8.8user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has str...
CVE-2020-14149HIGH7.5In uftpd before 2.12, handle_CWD in ftpcmd.c mishandled the path provided by the user, causing a NULL pointer dereferenc...
CVE-2020-14148HIGH7.5The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the...
CVE-2020-14147HIGH7.7An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with...
CVE-2020-14153HIGH7.1In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now