2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-9040HIGH7.5Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intende...
CVE-2020-13866HIGH7.8WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges...
CVE-2020-8172HIGH7.4TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
CVE-2020-6110HIGH8.8An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages incl...
CVE-2020-4529HIGH7.4IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authe...
CVE-2020-12773HIGH8.8A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows at...
CVE-2020-13912HIGH7.3SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, b...
CVE-2020-13902HIGH7.1ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c duri...
CVE-2020-13895HIGH8.8Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA sign...
CVE-2020-13894HIGH7.5handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the sa...
CVE-2020-13881HIGH7.5In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel ...
CVE-2020-13871HIGH7.5SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions i...
CVE-2020-13646HIGH7.8In Cheetah free WiFi 5.1, the driver file (liebaonat.sys) allows local users to cause a denial of service (BSOD) or poss...
CVE-2020-5591HIGH7.5XACK DNS 1.11.0 to 1.11.4, 1.10.0 to 1.10.8, 1.8.0 to 1.8.23, 1.7.0 to 1.7.18, and versions before 1.7.0 allow remote at...
CVE-2020-10063HIGH7.5A remote adversary with the ability to send arbitrary CoAP packets to be parsed by Zephyr is able to cause a denial of s...
CVE-2020-10061HIGH8.8Improper handling of the full-buffer case in the Zephyr Bluetooth implementation can result in memory corruption. This i...
CVE-2020-8103HIGH7.1A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user ...
CVE-2020-4449HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive in...
CVE-2020-4229HIGH7.3IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, w...
CVE-2020-9859HIGH7.8A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13....
CVE-2020-12723HIGH7.5regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_c...
CVE-2020-11492HIGH7.8An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe p...
CVE-2020-10878HIGH8.6Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A craft...
CVE-2020-10543HIGH8.2Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers...
CVE-2020-13842HIGH7.8An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT com...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now