2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-11136CRITICAL9.8Buffer Over-read in audio driver while using malloc management function due to not returning NULL for zero sized memory ...
CVE-2020-27221CRITICAL9.8In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtua...
CVE-2020-14756CRITICAL9.8Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio...
CVE-2020-35929CRITICAL9.8In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to...
CVE-2020-28480CRITICAL9.8The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com...
CVE-2020-35129CRITICAL9Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, cou...
CVE-2020-35128CRITICAL9Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, ...
CVE-2020-28472CRITICAL9.8This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an at...
CVE-2020-24640CRITICAL9.8There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a contai...
CVE-2020-24639CRITICAL9.8There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containe...
CVE-2020-29495CRITICAL10DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A ...
CVE-2020-29493CRITICAL9.8DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote u...
CVE-2020-16045CRITICAL9.6Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromis...
CVE-2020-29016CRITICAL9.8A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauth...
CVE-2020-29015CRITICAL9.8A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauth...
CVE-2020-27267CRITICAL9.1KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-...
CVE-2020-27265CRITICAL9.8KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC...
CVE-2020-27263CRITICAL9.1KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC...
CVE-2020-9142CRITICAL9.1There is a heap base buffer overflow vulnerability in some Huawei smartphone.Successful exploitation of this vulnerabili...
CVE-2020-9141CRITICAL9.1There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulner...
CVE-2020-9140CRITICAL9.8There is a vulnerability with buffer access with incorrect length value in some Huawei Smartphone.Unauthorized users may...
CVE-2020-9139CRITICAL9.1There is a improper input validation vulnerability in some Huawei Smartphone.Successful exploit of this vulnerability ca...
CVE-2020-9145CRITICAL9.1There is an Out-of-bounds Write vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability m...
CVE-2020-27488CRITICAL9.8Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is ba...
CVE-2020-9144CRITICAL9.8There is a heap overflow vulnerability in some Huawei smartphone, attackers can exploit this vulnerability to cause heap...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now