2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8262MEDIUM6.1A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Sit...
CVE-2020-8261MEDIUM4.3A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
CVE-2020-8260HIGH7.2A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform...
CVE-2020-8255MEDIUM4.9A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform...
CVE-2020-8254HIGH8.8A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to ...
CVE-2020-8250HIGH7.8A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
CVE-2020-8249HIGH7.8A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflo...
CVE-2020-8248HIGH7.8A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
CVE-2020-8241HIGH7.5A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end user...
CVE-2020-8240HIGH7.8A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use syste...
CVE-2020-8239CRITICAL9.8A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation att...
CVE-2020-6829MEDIUM5.3When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial i...
CVE-2020-5145HIGH8.6SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerabili...
CVE-2020-5144HIGH7.8SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SY...
CVE-2020-27957MEDIUM5.4The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certa...
CVE-2020-27956CRITICAL9.8An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the use...
CVE-2020-16140MEDIUM6.1The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.
CVE-2020-9982MEDIUM5.5This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 ...
CVE-2020-9979MEDIUM5.5A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An att...
CVE-2020-9973HIGH7.8An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.7, Securi...
CVE-2020-9961HIGH7.8An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.7, Secur...
CVE-2020-9941HIGH7.5This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 H...
CVE-2020-9932HIGH8.8A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPa...
CVE-2020-9866CRITICAL9.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.6, Security U...
CVE-2020-9860MEDIUM5.4A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 13.0.5. P...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now