2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-8435HIGH8.1An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analyti...
CVE-2020-10478HIGH8.8CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settin...
CVE-2020-10390HIGH7.2OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Stand...
CVE-2020-10389HIGH7.2admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by i...
CVE-2020-10386HIGH7.2admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Exe...
CVE-2020-7254HIGH7.8Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4....
CVE-2020-7943HIGH7.5Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For Pup...
CVE-2020-5958HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which...
CVE-2020-9408HIGH8.8The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO ...
CVE-2020-1981HIGH7.8A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local at...
CVE-2020-1980HIGH7.8A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted she...
CVE-2020-1979HIGH7.8A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge...
CVE-2020-6209HIGH7.5SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allo...
CVE-2020-6208HIGH8.2SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic...
CVE-2020-6202HIGH7.2SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does...
CVE-2020-6196HIGH7.5SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which...
CVE-2020-0085HIGH7.8In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. Th...
CVE-2020-0084HIGH7.8In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local e...
CVE-2020-0063HIGH7.3In SurfaceFlinger, it is possible to override UI confirmation screen protected by the TEE. This could lead to local esca...
CVE-2020-0062HIGH7.5In Euicc, there is a possible information disclosure due to an included test Certificate. This could lead to remote info...
CVE-2020-0054HIGH7.8In WifiNetworkSuggestionsManager of WifiNetworkSuggestionsManager.java, there is a possible permission revocation due to...
CVE-2020-0051HIGH7.8In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of p...
CVE-2020-0046HIGH7.8In DrmPlugin::releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow...
CVE-2020-0083HIGH7.5In setRequirePmfInternal of sta_network.cpp, there is a possible default value being improperly applied due to a logic e...
CVE-2020-0069HIGH7.8In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now