2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-23653CRITICAL9.8An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/...
CVE-2020-5685CRITICAL9.8UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands ...
CVE-2020-5633CRITICAL9.8Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen...
CVE-2020-25226CRITICAL9.8A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),...
CVE-2020-15800CRITICAL9.8A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),...
CVE-2020-35458CRITICAL9.8An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk...
CVE-2020-26712CRITICAL9.8REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses t...
CVE-2020-14275CRITICAL9.8Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could al...
CVE-2020-27637CRITICAL9.8The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to...
CVE-2020-0471CRITICAL9.8In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetoot...
CVE-2020-24027CRITICAL9.8In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling o...
CVE-2020-11995CRITICAL9.8A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code exec...
CVE-2020-35205CRITICAL9.8Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attacker...
CVE-2020-16025CRITICAL9.6Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised t...
CVE-2020-16024CRITICAL9.6Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rend...
CVE-2020-16018CRITICAL9.6Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rend...
CVE-2020-16017CRITICAL9.6Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised t...
CVE-2020-16016CRITICAL9.6Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromis...
CVE-2020-16014CRITICAL9.6Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rendere...
CVE-2020-35131CRITICAL9.8Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCrite...
CVE-2020-8584CRITICAL9.8Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remot...
CVE-2020-7794CRITICAL9.8This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the ...
CVE-2020-7784CRITICAL9.8This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of pac...
CVE-2020-28468CRITICAL9.8This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulner...
CVE-2020-13452CRITICAL9.8In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now