2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-10882HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch...
CVE-2020-9552HIGH7.8Adobe Bridge versions 10.0 have a heap-based buffer overflow vulnerability. Successful exploitation could lead to arbitr...
CVE-2020-9551HIGH7.8Adobe Bridge versions 10.0 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary co...
CVE-2020-3769HIGH7.5Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful ex...
CVE-2020-3761HIGH7.5ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a remote file read vulnerability. Successful exploitation ...
CVE-2020-5281HIGH7.5In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from P...
CVE-2020-5280HIGH7.5http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies...
CVE-2020-3806HIGH7.5Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20...
CVE-2020-3804HIGH7.5Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20...
CVE-2020-3803HIGH7.8Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20...
CVE-2020-3802HIGH8.8Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20...
CVE-2020-3800HIGH7.5Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20...
CVE-2020-3766HIGH7.8Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Succes...
CVE-2020-2171HIGH8.8Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attack...
CVE-2020-2168HIGH8.8Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation...
CVE-2020-2167HIGH8.8Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of ...
CVE-2020-2166HIGH8.8Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of a...
CVE-2020-2165HIGH7.5Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins ...
CVE-2020-2160HIGH8.8Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows att...
CVE-2020-10649HIGH7.8DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code exec...
CVE-2020-9375HIGH7.5TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a ...
CVE-2020-5558HIGH8.8CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
CVE-2020-8985HIGH8.8ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
CVE-2020-8984HIGH7.5lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
CVE-2020-7001HIGH7.5In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now