2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-3221HIGH8.6A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Seri...
CVE-2020-3219HIGH8.8A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execu...
CVE-2020-3218HIGH7.2A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative...
CVE-2020-3217HIGH8.8A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Software, Cisco IOS XE ...
CVE-2020-3212HIGH7.2A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrar...
CVE-2020-3211HIGH7.2A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrar...
CVE-2020-3205HIGH8.8A vulnerability in the implementation of the inter-VM channel of Cisco IOS Software for Cisco 809 and 829 Industrial Int...
CVE-2020-3203HIGH8.6A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst 9800 Series Wireless...
CVE-2020-3200HIGH7.7A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Software could allow an aut...
CVE-2020-3199HIGH8.8Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Ro...
CVE-2020-13787HIGH7.5D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.
CVE-2020-13786HIGH8.8D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.
CVE-2020-13785HIGH7.5D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.
CVE-2020-13784HIGH7.5D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.
CVE-2020-13783HIGH7.5D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.
CVE-2020-13782HIGH8.8D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.
CVE-2020-12846HIGH8Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is pot...
CVE-2020-4180HIGH8.8IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By s...
CVE-2020-7117HIGH7.2The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the atta...
CVE-2020-7116HIGH7.2The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the atta...
CVE-2020-2200HIGH8.8Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master ...
CVE-2020-2196HIGH8Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perfor...
CVE-2020-13764HIGH7.5common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not con...
CVE-2020-12607HIGH7.5An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the poin...
CVE-2020-13763HIGH7.5In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now