2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6971HIGH7.8In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, ...
CVE-2020-5957HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which...
CVE-2020-9418HIGH7.8An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attack...
CVE-2020-4278HIGH7.8IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user...
CVE-2020-10174HIGH7init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the pr...
CVE-2020-9544HIGH7.5An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authenticat...
CVE-2020-9402HIGH8.8Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a ...
CVE-2020-10173HIGH8.8Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabiliti...
CVE-2020-10101HIGH7.5An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sen...
CVE-2020-10096HIGH7.5An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memor...
CVE-2020-8661HIGH7.5CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
CVE-2020-8659HIGH7.5CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many...
CVE-2020-7130HIGH7.5HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard ...
CVE-2020-9476HIGH7.5ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login...
CVE-2020-9372HIGH7.8The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or ...
CVE-2020-3155HIGH7.4A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, re...
CVE-2020-3148HIGH7.1A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remot...
CVE-2020-3128HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros...
CVE-2020-3127HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros...
CVE-2020-10057HIGH8.8GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an ...
CVE-2020-7988HIGH8.8An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any u...
CVE-2020-5536HIGH8.8OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentica...
CVE-2020-5535HIGH8.8OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary...
CVE-2020-1734HIGH7.4A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses s...
CVE-2020-5403HIGH7.5Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now