2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-13817HIGH7.4ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit o...
CVE-2020-13777HIGH7.4GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS...
CVE-2020-6496HIGH8.8Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perf...
CVE-2020-6453HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially expl...
CVE-2020-6419HIGH8.8Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap c...
CVE-2020-11080HIGH7.5In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of ...
CVE-2020-13790HIGH8.1libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PP...
CVE-2020-13379HIGH8.2The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows ...
CVE-2020-7014HIGH8.8The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 cont...
CVE-2020-7013HIGH7.2Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privil...
CVE-2020-7012HIGH8.8Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authen...
CVE-2020-7010HIGH7.5Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an...
CVE-2020-3281HIGH8.8A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authent...
CVE-2020-3267HIGH7.1A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated,...
CVE-2020-3257HIGH8.1Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Ro...
CVE-2020-3238HIGH8.1A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an aut...
CVE-2020-3235HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa...
CVE-2020-3234HIGH8.8A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated ...
CVE-2020-3232HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) implementation in Cisco ASR 920 Series Aggregation Serv...
CVE-2020-3230HIGH7.5A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software and Cisco IOS XE Sof...
CVE-2020-3229HIGH8.8A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a ...
CVE-2020-3228HIGH8.6A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX...
CVE-2020-3226HIGH8.6A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS XE Software could a...
CVE-2020-3225HIGH8.6Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature of Cisco IOS Software and...
CVE-2020-3224HIGH8.8A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now