2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-7079HIGH7.8An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code executio...
CVE-2020-11877HIGH7.5airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC e...
CVE-2020-11876HIGH7.5airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of a...
CVE-2020-9523HIGH8.8Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting ...
CVE-2020-4277HIGH7.5IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an att...
CVE-2020-11875HIGH7.8An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK ke...
CVE-2020-11874HIGH7.5An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory ...
CVE-2020-11793HIGH8.8A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allow...
CVE-2020-10947HIGH8.8Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
CVE-2020-10813HIGH7.5A buffer overflow vulnerability in FTPDMIN 0.96 allows attackers to crash the server via a crafted packet.
CVE-2020-11872HIGH7.5The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests bef...
CVE-2020-11868HIGH7.5ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronizatio...
CVE-2020-7486HIGH7.5**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in...
CVE-2020-7484HIGH7.5**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of servi...
CVE-2020-7483HIGH7.5**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the '...
CVE-2020-7111HIGH7.2A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Co...
CVE-2020-2180HIGH8.8Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty...
CVE-2020-2179HIGH8.8Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ...
CVE-2020-2178HIGH7.1Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XX...
CVE-2020-11826HIGH7.5Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. Ho...
CVE-2020-11825HIGH8.8In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any use...
CVE-2020-11818HIGH8.8In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed w...
CVE-2020-4347HIGH7.3IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to ...
CVE-2020-3651HIGH7.5Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames....
CVE-2020-9280HIGH7.5In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the de...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now