2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28351MEDIUM6.1The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r...
CVE-2020-28349MEDIUM6.5An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplin...
CVE-2020-24407CRITICAL9.1Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result i...
CVE-2020-24406LOW3.7When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulner...
CVE-2020-24405MEDIUM4.3Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inve...
CVE-2020-24404LOW2.7Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integr...
CVE-2020-24403LOW2.7Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the I...
CVE-2020-24402MEDIUM4.9Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integratio...
CVE-2020-24401MEDIUM6.5Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can st...
CVE-2020-24400HIGH7.1Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensiti...
CVE-2020-28347CRITICAL9.8tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl...
CVE-2020-7764HIGH7.5This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by...
CVE-2020-28345HIGH7.5An issue was discovered on LG mobile devices with Android OS 10 software. The Wi-Fi subsystem may crash because of the l...
CVE-2020-28344HIGH7.5An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. System services may crash b...
CVE-2020-28343HIGH7.8An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software...
CVE-2020-28342HIGH7.8An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software. The S Secure applica...
CVE-2020-28341HIGH7.8An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Elemen...
CVE-2020-28340CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypa...
CVE-2020-28339HIGH8.8The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usc...
CVE-2020-16122HIGH7.8PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository tru...
CVE-2020-16121LOW3.3PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mim...
CVE-2020-28168MEDIUM5.9Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass...
CVE-2020-15259HIGH8.8ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result ...
CVE-2020-3604HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could al...
CVE-2020-3603HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could al...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now