2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-1613HIGH7.5A vulnerability in the BGP FlowSpec implementation may cause a Juniper Networks Junos OS device to terminate an establis...
CVE-2020-1991HIGH7.1An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escala...
CVE-2020-1990HIGH7.2A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to...
CVE-2020-1989HIGH7.8An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global...
CVE-2020-1985HIGH7.8Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite...
CVE-2020-1984HIGH7.8Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create fol...
CVE-2020-10976HIGH7.5GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.
CVE-2020-11605HIGH7.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive informat...
CVE-2020-5735HIGH8.8Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacke...
CVE-2020-5550HIGH8.1Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows r...
CVE-2020-5549HIGH8.8Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and ...
CVE-2020-11629HIGH7.2An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, whi...
CVE-2020-11627HIGH8.8An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has b...
CVE-2020-10366HIGH7.5LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-...
CVE-2020-11620HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-11619HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-11612HIGH7.5The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte st...
CVE-2020-11610HIGH8.8An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js spec...
CVE-2020-11560HIGH7.8NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
CVE-2020-11561HIGH8.8In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged fun...
CVE-2020-7615HIGH7.8fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep....
CVE-2020-7613HIGH8.1clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_...
CVE-2020-5734HIGH7.5Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by...
CVE-2020-11587HIGH7.5An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request a...
CVE-2020-11599HIGH7.5An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the us...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now