2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-8829HIGH8.8CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.
CVE-2020-7983HIGH8.1A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF...
CVE-2020-12104HIGH8.8The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via...
CVE-2020-12657HIGH7.8An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bf...
CVE-2020-12653HIGH7.8An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marv...
CVE-2020-12654HIGH7.1An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wm...
CVE-2020-12649HIGH7.5Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths.
CVE-2020-5343HIGH7.8Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecu...
CVE-2020-5335HIGH8.8RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthentic...
CVE-2020-5332HIGH7.2RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious us...
CVE-2020-10622HIGH7.8LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorize...
CVE-2020-12642HIGH7.5An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resulta...
CVE-2020-12109HIGH8.8Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 ...
CVE-2020-12111HIGH8.8Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
CVE-2020-11671HIGH8.1Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid...
CVE-2020-11462HIGH7.5An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interf...
CVE-2020-11443HIGH8.1The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoo...
CVE-2020-10876HIGH7.5The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its tim...
CVE-2020-10187HIGH7.5Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve ...
CVE-2020-11842HIGH7.5Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier...
CVE-2020-8018HIGH7.8A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of ...
CVE-2020-7351HIGH8.8An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allo...
CVE-2020-11028HIGH7.5In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated discl...
CVE-2020-11027HIGH8.1In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user passwo...
CVE-2020-11016HIGH8.8IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled me...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now