2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8272HIGH7.5Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1...
CVE-2020-8271CRITICAL9.8Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 1...
CVE-2020-8270HIGH8.8An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD version...
CVE-2020-8269HIGH8.8An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, ...
CVE-2020-8259HIGH8.1Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the...
CVE-2020-8152MEDIUM4.4Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the...
CVE-2020-5666HIGH7.5Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '...
CVE-2020-2492HIGH7.2If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue...
CVE-2020-2490HIGH7.2If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue...
CVE-2020-25695HIGH8.8A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9...
CVE-2020-25694HIGH8.1A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9...
CVE-2020-28268HIGH7.5Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial o...
CVE-2020-7772CRITICAL9.8This affects the package doc-path before 2.1.2.
CVE-2020-28638CRITICAL9.8ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing a...
CVE-2020-15481HIGH7.8An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 B...
CVE-2020-6157MEDIUM4.3Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a mal...
CVE-2020-5796HIGH7.8Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the...
CVE-2020-27217HIGH7.5In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received fro...
CVE-2020-13638CRITICAL9.8lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account cr...
CVE-2020-12338CRITICAL9.8Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user t...
CVE-2020-12313HIGH8.8Insufficient control flow management in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an u...
CVE-2020-0599MEDIUM6.7Improper access control in the PMC for some Intel(R) Processors may allow a privileged user to potentially enable escala...
CVE-2020-7962MEDIUM5.3An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It i...
CVE-2020-26230MEDIUM5.3Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identific...
CVE-2020-26223MEDIUM6.5Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now