2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-4362HIGH8.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerabilit...
CVE-2020-11668HIGH7.1In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles i...
CVE-2020-1895HIGH7.8A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dim...
CVE-2020-9499HIGH7.2Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker ...
CVE-2020-10629HIGH7.5WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker...
CVE-2020-10617HIGH7.5There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0....
CVE-2020-10603HIGH8.8WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system...
CVE-2020-11557HIGH7.5An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password va...
CVE-2020-11555HIGH7.5An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sen...
CVE-2020-11554HIGH7.5An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sen...
CVE-2020-11553HIGH8.8An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
CVE-2020-10551HIGH7.8QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to th...
CVE-2020-11655HIGH7.5SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function...
CVE-2020-11653HIGH7.5An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occu...
CVE-2020-11650HIGH7.5An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a deni...
CVE-2020-8828HIGH8.8As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster o...
CVE-2020-8827HIGH7.5As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other...
CVE-2020-8826HIGH7.5As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, ...
CVE-2020-1885HIGH7.8Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows ...
CVE-2020-1639HIGH7.5When an attacker sends a specific crafted Ethernet Operation, Administration, and Maintenance (Ethernet OAM) packet to a...
CVE-2020-1638HIGH7.5The FPC (Flexible PIC Concentrator) of Juniper Networks Junos OS and Junos OS Evolved may restart after processing a spe...
CVE-2020-1634HIGH7.5On High-End SRX Series devices, in specific configurations and when specific networking events or operator actions occur...
CVE-2020-1627HIGH7.5A vulnerability in Juniper Networks Junos OS on vMX and MX150 devices may allow an attacker to cause a Denial of Service...
CVE-2020-1626HIGH7.5A vulnerability in Juniper Networks Junos OS Evolved may allow an attacker to cause a Denial of Service (DoS) by sending...
CVE-2020-1617HIGH7.5This issue occurs on Juniper Networks Junos OS devices which do not support Advanced Forwarding Interface (AFI) / Advanc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now