2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-10787HIGH8.8An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the...
CVE-2020-10786HIGH8.8A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary co...
CVE-2020-1967HIGH7.5Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due...
CVE-2020-11828HIGH7.5In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger su...
CVE-2020-11968HIGH7.5In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. N...
CVE-2020-11964HIGH7.5In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the roo...
CVE-2020-11958HIGH7.8re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.
CVE-2020-9276HIGH8.8An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests sup...
CVE-2020-11010HIGH8.8In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when fi...
CVE-2020-11946HIGH7.5Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
CVE-2020-3946HIGH7.5InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 ...
CVE-2020-11753HIGH8.8An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user wi...
CVE-2020-5569HIGH8.4An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is s...
CVE-2020-11886HIGH8.1OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or s...
CVE-2020-11885HIGH7.2WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the X...
CVE-2020-1751HIGH7An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifi...
CVE-2020-0082HIGH7.8In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe dese...
CVE-2020-0081HIGH7.8In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local esc...
CVE-2020-0080HIGH7.8In onOpActiveChanged and related methods of AppOpsControllerImpl.java, there is a possible way to display an app overlay...
CVE-2020-0079HIGH7.8In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to loc...
CVE-2020-0078HIGH7.8In releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This coul...
CVE-2020-7085HIGH7.8A heap overflow vulnerability in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution o...
CVE-2020-7082HIGH8.8A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a syste...
CVE-2020-7081HIGH8.8A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write ...
CVE-2020-7080HIGH7.8A buffer overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitrary code execution...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now