2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-7939HIGH8.8SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. ...
CVE-2020-7938HIGH8.8plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up t...
CVE-2020-7220HIGH7.5HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount i...
CVE-2020-7931HIGH8.8In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modif...
CVE-2020-5221HIGH7.2In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple ...
CVE-2020-7595HIGH7.5xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
CVE-2020-7594HIGH7.2MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitra...
CVE-2020-7040HIGH8.1storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks tha...
CVE-2020-6638HIGH7.5Grin through 2.1.1 has Insufficient Validation.
CVE-2020-6849HIGH8.8The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with r...
CVE-2020-7213HIGH7.5Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date...
CVE-2020-7211HIGH7.5tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
CVE-2020-7246HIGH8.8A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code ...
CVE-2020-7244HIGH7.2Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav...
CVE-2020-7243HIGH7.2Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav...
CVE-2020-7242HIGH7.2Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav...
CVE-2020-7241HIGH7.5The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/...
CVE-2020-7240HIGH8.8Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS ...
CVE-2020-7237HIGH8.8Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug L...
CVE-2020-7232HIGH7.5Evoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and passw...
CVE-2020-5398HIGH7.5In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, ...
CVE-2020-7047HIGH8.8The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal perm...
CVE-2020-7105HIGH7.5async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return valu...
CVE-2020-7044HIGH7.5In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c b...
CVE-2020-3941HIGH7The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now