2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-10682HIGH7.8The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1...
CVE-2020-10669HIGH7.5The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the...
CVE-2020-7006HIGH8.4Systech Corporation NDS-5000 Terminal Server, NDS/5008 (8 Port, RJ45), firmware Version 02D.30. Successful exploitation ...
CVE-2020-10671HIGH8.8The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-...
CVE-2020-3266HIGH7.8A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbi...
CVE-2020-3265HIGH7.8A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to ...
CVE-2020-3264HIGH7.1A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflo...
CVE-2020-1705HIGH7A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an i...
CVE-2020-10678HIGH8.8In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an...
CVE-2020-10675HIGH7.5The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via...
CVE-2020-10648HIGH7.8Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images ...
CVE-2020-10673HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-10672HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9326HIGH7.5BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 ...
CVE-2020-9325HIGH7.5Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.
CVE-2020-9324HIGH7.5Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.
CVE-2020-7002HIGH7.8Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be explo...
CVE-2020-8470HIGH7.5Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl...
CVE-2020-8468HIGH8.8Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a co...
CVE-2020-8467HIGH8.8A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow r...
CVE-2020-3950HIGH7.8VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for ...
CVE-2020-10120HIGH7.2cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
CVE-2020-10115HIGH7.2cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
CVE-2020-9346HIGH8.8Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attack...
CVE-2020-8787HIGH7.5SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submit...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now