2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7752HIGH8.8This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker...
CVE-2020-27187HIGH7.8An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic...
CVE-2020-7197CRITICAL9.8SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off nod...
CVE-2020-7196MEDIUM6.5The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of han...
CVE-2020-7127CRITICAL9.8A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Pri...
CVE-2020-7126MEDIUM5.8A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to ...
CVE-2020-7125HIGH8.8A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
CVE-2020-7124CRITICAL9.8A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
CVE-2020-6876MEDIUM5.4A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of cl...
CVE-2020-24632HIGH7.2A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1....
CVE-2020-24631HIGH7.2A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3...
CVE-2020-18766CRITICAL9.6A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.
CVE-2020-15897HIGH7.5Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attack...
CVE-2020-13100HIGH7.5Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x bef...
CVE-2020-25470MEDIUM6.1AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added sit...
CVE-2020-7751HIGH7.2pathval before version 1.1.1 is vulnerable to prototype pollution.
CVE-2020-27678CRITICAL9.8An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and Sm...
CVE-2020-27388MEDIUM5.4Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An au...
CVE-2020-24848HIGH7.8FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform ...
CVE-2020-24847MEDIUM4.3A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protect...
CVE-2020-5990HIGH7.8NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which m...
CVE-2020-5978HIGH7.8NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in its services in which a folder i...
CVE-2020-5977HIGH7.8NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Ser...
CVE-2020-25483CRITICAL9.8An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an atta...
CVE-2020-25466CRITICAL9.8A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now