2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-7982HIGH8.1An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the...
CVE-2020-7919HIGH7.5Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 f...
CVE-2020-7248HIGH7.5libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that...
CVE-2020-9471HIGH8.8Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package...
CVE-2020-9321HIGH7.5configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents f...
CVE-2020-6582HIGH7.5Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a la...
CVE-2020-6581HIGH7.3Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and ...
CVE-2020-5849HIGH7.5Unraid 6.8.0 allows authentication bypass.
CVE-2020-5844HIGH7.2index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t...
CVE-2020-3948HIGH7.8Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privi...
CVE-2020-3947HIGH8.8VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. ...
CVE-2020-6988HIGH7.5Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont...
CVE-2020-6984HIGH7.5Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont...
CVE-2020-6585HIGH8.8Nagios Log Server 2.1.3 has CSRF.
CVE-2020-10241HIGH8.8An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSR...
CVE-2020-10239HIGH8.8An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows acc...
CVE-2020-10238HIGH7.5An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading...
CVE-2020-10557HIGH8.8An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged ...
CVE-2020-5546HIGH8.8Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function include...
CVE-2020-9290HIGH7.8An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attack...
CVE-2020-9287HIGH7.8An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with ...
CVE-2020-10591HIGH7.5An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potential...
CVE-2020-10589HIGH7.8v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user...
CVE-2020-10588HIGH7.8v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by...
CVE-2020-8141HIGH8.8The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now