2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26077MEDIUM4.3A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticat...
CVE-2020-26076HIGH7.5A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensit...
CVE-2020-26075HIGH8.8A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker ...
CVE-2020-26072HIGH8.7A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker ...
CVE-2020-26068MEDIUM6.5A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authentic...
CVE-2020-28367HIGH7.5Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time ...
CVE-2020-28366HIGH7.5Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time ...
CVE-2020-28362HIGH7.5Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
CVE-2020-28091HIGH7.5cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame...
CVE-2020-26933MEDIUM6Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1....
CVE-2020-26554MEDIUM6.1REDDOXX MailDepot 2033 (aka 2.3.3022) allows XSS via an incoming HTML e-mail message.
CVE-2020-28005MEDIUM6.5httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffe...
CVE-2020-26884MEDIUM6.1RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could ...
CVE-2020-25406HIGH7.3app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.
CVE-2020-24297HIGH8.8httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS com...
CVE-2020-6016CRITICAL9.8Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in ...
CVE-2020-28724MEDIUM6.1Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
CVE-2020-7564HIGH8.8A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server...
CVE-2020-7563HIGH8.8A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premi...
CVE-2020-7562HIGH8.1A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premiu...
CVE-2020-28361MEDIUM5.4Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allow...
CVE-2020-24723MEDIUM4.8Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & L...
CVE-2020-28917MEDIUM6.5An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves...
CVE-2020-28915MEDIUM5.8A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local...
CVE-2020-28183CRITICAL9.8SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to proce...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now