2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-11501HIGH7.4GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) bec...
CVE-2020-11500HIGH7.5Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all pa...
CVE-2020-11498HIGH8.8Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code ...
CVE-2020-9067HIGH8There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to p...
CVE-2020-8835HIGH7.8In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bou...
CVE-2020-11444HIGH8.8Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
CVE-2020-11107HIGH8.8An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged...
CVE-2020-8423HIGH7.2A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated...
CVE-2020-9349HIGH7.5The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service wit...
CVE-2020-11451HIGH7.2The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archiv...
CVE-2020-11450HIGH7.5Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information throu...
CVE-2020-11100HIGH8.8In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can w...
CVE-2020-8016HIGH7A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise M...
CVE-2020-11490HIGH7.2Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via...
CVE-2020-8015HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attacke...
CVE-2020-8146HIGH7.8In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file del...
CVE-2020-8144HIGH8.4The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under cert...
CVE-2020-6096HIGH8.1An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calli...
CVE-2020-11469HIGH7.8Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during install...
CVE-2020-11467HIGH7.2An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface...
CVE-2020-11465HIGH8.8An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privi...
CVE-2020-11463HIGH7.5An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user'...
CVE-2020-10204HIGH7.2Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
CVE-2020-10199HIGH8.8Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
CVE-2020-9785HIGH7.8Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.4 and iPa...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now