2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11501 | HIGH | 7.4 | 3.4% | Apr 3, 2020 | GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) bec... |
| CVE-2020-11500 | HIGH | 7.5 | 1.3% | Apr 3, 2020 | Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all pa... |
| CVE-2020-11498 | HIGH | 8.8 | 3.4% | Apr 2, 2020 | Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code ... |
| CVE-2020-9067 | HIGH | 8 | 0.6% | Apr 2, 2020 | There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to p... |
| CVE-2020-8835 | HIGH | 7.8 | 6.1% | Apr 2, 2020 | In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bou... |
| CVE-2020-11444 | HIGH | 8.8 | 8.5% | Apr 2, 2020 | Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control. |
| CVE-2020-11107 | HIGH | 8.8 | 22.5% | Apr 2, 2020 | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged... |
| CVE-2020-8423 | HIGH | 7.2 | 9.3% | Apr 2, 2020 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated... |
| CVE-2020-9349 | HIGH | 7.5 | 1.5% | Apr 2, 2020 | The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service wit... |
| CVE-2020-11451 | HIGH | 7.2 | 2.7% | Apr 2, 2020 | The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archiv... |
| CVE-2020-11450 | HIGH | 7.5 | 17.8% | Apr 2, 2020 | Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information throu... |
| CVE-2020-11100 | HIGH | 8.8 | 60.7% | Apr 2, 2020 | In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can w... |
| CVE-2020-8016 | HIGH | 7 | 0.3% | Apr 2, 2020 | A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise M... |
| CVE-2020-11490 | HIGH | 7.2 | 1.9% | Apr 2, 2020 | Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via... |
| CVE-2020-8015 | HIGH | 7.8 | 0.5% | Apr 2, 2020 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attacke... |
| CVE-2020-8146 | HIGH | 7.8 | 0.5% | Apr 1, 2020 | In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file del... |
| CVE-2020-8144 | HIGH | 8.4 | 0.7% | Apr 1, 2020 | The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under cert... |
| CVE-2020-6096 | HIGH | 8.1 | 5.2% | Apr 1, 2020 | An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calli... |
| CVE-2020-11469 | HIGH | 7.8 | 0.4% | Apr 1, 2020 | Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during install... |
| CVE-2020-11467 | HIGH | 7.2 | 4.0% | Apr 1, 2020 | An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface... |
| CVE-2020-11465 | HIGH | 8.8 | 1.9% | Apr 1, 2020 | An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privi... |
| CVE-2020-11463 | HIGH | 7.5 | 1.8% | Apr 1, 2020 | An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user'... |
| CVE-2020-10204 | HIGH | 7.2 | 24.3% | Apr 1, 2020 | Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution. |
| CVE-2020-10199 | HIGH | 8.8 | 99.1% | Apr 1, 2020 | Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). |
| CVE-2020-9785 | HIGH | 7.8 | 1.3% | Apr 1, 2020 | Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.4 and iPa... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now