2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-8509HIGH7.5Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading t...
CVE-2020-5527HIGH7.5When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (al...
CVE-2020-5551HIGH8.8Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a d...
CVE-2020-10940HIGH7.8Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.
CVE-2020-6095HIGH7.5An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14...
CVE-2020-10939HIGH7.8Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.
CVE-2020-10954HIGH7.5GitLab through 12.9 is affected by a potential DoS in repository archive download.
CVE-2020-10953HIGH7.5In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
CVE-2020-10817HIGH8.8The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress all...
CVE-2020-5863HIGH8.6In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can c...
CVE-2020-5862HIGH7.5On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop process...
CVE-2020-5861HIGH7.5On BIG-IP 12.1.0-12.1.5, the TMM process may produce a core file in some cases when Ram Cache incorrectly optimizes stor...
CVE-2020-5860HIGH8.1On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0....
CVE-2020-5859HIGH7.5On BIG-IP 15.1.0.1, specially formatted HTTP/3 messages may cause TMM to produce a core file.
CVE-2020-5858HIGH7.8On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-...
CVE-2020-5857HIGH7.5On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, undisclosed HTTP behavior...
CVE-2020-10607HIGH8.8In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper...
CVE-2020-1773HIGH8.1An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or b...
CVE-2020-1772HIGH7.5It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid...
CVE-2020-10508HIGH7.5Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a spe...
CVE-2020-3921HIGH7.5UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts informa...
CVE-2020-3920HIGH8.1UltraLog Express device management interface does not properly perform access authentication in some specific pages/func...
CVE-2020-9521HIGH8.8An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.0...
CVE-2020-9066HIGH7.8Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vuln...
CVE-2020-7944HIGH7.7In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now