2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6090HIGH7.2An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03...
CVE-2020-12712HIGH7.5A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an...
CVE-2020-5593HIGH8.8Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a ...
CVE-2020-13855HIGH7.2Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manag...
CVE-2020-13852HIGH7.2Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
CVE-2020-13851HIGH8.8Artica Pandora FMS 7.44 allows remote command execution via the events feature.
CVE-2020-13850HIGH7.5Artica Pandora FMS 7.44 has inadequate access controls on a web folder.
CVE-2020-12850HIGH7The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Ce...
CVE-2020-12713HIGH7.2An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and Ci...
CVE-2020-11090HIGH7.5In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling co...
CVE-2020-13900HIGH7.5An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NUL...
CVE-2020-13899HIGH7.5An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in jan...
CVE-2020-13898HIGH7.5An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL...
CVE-2020-13238HIGH7.5Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthe...
CVE-2020-11622HIGH7.5A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below...
CVE-2020-10705HIGH7.5A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-con...
CVE-2020-13906HIGH7.8IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038eb7.
CVE-2020-13905HIGH8.8IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038ed4.
CVE-2020-13445HIGH8.8In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6...
CVE-2020-13223HIGH7.5HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials....
CVE-2020-2032HIGH7A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to ex...
CVE-2020-2029HIGH7.2An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to exec...
CVE-2020-2028HIGH7.2An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitra...
CVE-2020-2027HIGH7.2A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrato...
CVE-2020-2026HIGH8.8A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple cont...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now