2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-1940HIGH7.5The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 a...
CVE-2020-7799HIGH7.2An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Se...
CVE-2020-5523HIGH7.4Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificat...
CVE-2020-7998HIGH8.8An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerabili...
CVE-2020-5207HIGH7.5In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and T...
CVE-2020-7952HIGH7.8rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service ...
CVE-2020-7951HIGH7.8meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by cr...
CVE-2020-7950HIGH7.8meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by cr...
CVE-2020-7949HIGH7.8schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by ...
CVE-2020-7238HIGH7.5Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Tr...
CVE-2020-8009HIGH7.5AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.
CVE-2020-5522HIGH7.4The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-...
CVE-2020-5521HIGH7.4The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-t...
CVE-2020-5520HIGH7.4The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-midd...
CVE-2020-7991HIGH8.8Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
CVE-2020-7984HIGH7.5SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain ad...
CVE-2020-3142HIGH7.5A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated...
CVE-2020-3115HIGH8.8A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to...
CVE-2020-7596HIGH8.8Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
CVE-2020-5224HIGH8.8In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessio...
CVE-2020-6964HIGH8.6In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center...
CVE-2020-5219HIGH8.8Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userC...
CVE-2020-7226HIGH7.5CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excess...
CVE-2020-6007HIGH7.9Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handli...
CVE-2020-7940HIGH7.5Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now