2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26732HIGH7.5SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie ...
CVE-2020-28470MEDIUM6.1This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() funct...
CVE-2020-16119HIGH7.8Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an a...
CVE-2020-27267CRITICAL9.1KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-...
CVE-2020-27265CRITICAL9.8KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC...
CVE-2020-27263CRITICAL9.1KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC...
CVE-2020-9209MEDIUM6.7There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located impro...
CVE-2020-1866MEDIUM6.5There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended b...
CVE-2020-1865MEDIUM6.5There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the...
CVE-2020-14102HIGH7.2There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root priv...
CVE-2020-14101HIGH7.5The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi rout...
CVE-2020-14098HIGH7.5The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts....
CVE-2020-14097HIGH7.5Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6...
CVE-2020-9203LOW3.3There is a resource management errors vulnerability in Huawei P30. Local attackers construct broadcast message for some ...
CVE-2020-9143MEDIUM5.3There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability ...
CVE-2020-9142CRITICAL9.1There is a heap base buffer overflow vulnerability in some Huawei smartphone.Successful exploitation of this vulnerabili...
CVE-2020-9141CRITICAL9.1There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulner...
CVE-2020-9140CRITICAL9.8There is a vulnerability with buffer access with incorrect length value in some Huawei Smartphone.Unauthorized users may...
CVE-2020-9139CRITICAL9.1There is a improper input validation vulnerability in some Huawei Smartphone.Successful exploit of this vulnerability ca...
CVE-2020-9138MEDIUM5.3There is a heap-based buffer overflow vulnerability in some Huawei Smartphone, Successful exploit of this vulnerability ...
CVE-2020-35578HIGH7.2An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature...
CVE-2020-9145CRITICAL9.1There is an Out-of-bounds Write vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability m...
CVE-2020-27488CRITICAL9.8Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is ba...
CVE-2020-9144CRITICAL9.8There is a heap overflow vulnerability in some Huawei smartphone, attackers can exploit this vulnerability to cause heap...
CVE-2020-4604MEDIUM4.4IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local privile...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now