2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6424HIGH8.8Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap co...
CVE-2020-6422HIGH8.8Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap co...
CVE-2020-6420HIGH8.8Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass sam...
CVE-2020-10364HIGH7.5The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusa...
CVE-2020-10793HIGH8.8CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the ...
CVE-2020-6650HIGH8.8UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or ...
CVE-2020-10593HIGH7.5Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Servi...
CVE-2020-10592HIGH7.5Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Servi...
CVE-2020-10818HIGH7.2Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the ...
CVE-2020-10808HIGH8.8Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint....
CVE-2020-10802HIGH8In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain par...
CVE-2020-10804HIGH8In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current...
CVE-2020-10800HIGH8.1lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data...
CVE-2020-8882HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8881HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8880HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8878HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8136HIGH7.5Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing ...
CVE-2020-8134HIGH8.1Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external netw...
CVE-2020-9425HIGH7.5An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved...
CVE-2020-10792HIGH7.5openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placin...
CVE-2020-1864HIGH8.1Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain som...
CVE-2020-1709HIGH7.8A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulne...
CVE-2020-1707HIGH7A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification ...
CVE-2020-10597HIGH7.1Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Multiple out-of-bounds read vulnerabilities may be ex...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now