2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3459HIGH7.8A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary comma...
CVE-2020-3458MEDIUM6.7Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Th...
CVE-2020-3457MEDIUM6.7A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary comma...
CVE-2020-3456HIGH8.8A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remo...
CVE-2020-3455HIGH7.8A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass...
CVE-2020-3436HIGH8.6A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defe...
CVE-2020-3410HIGH8.1A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Softwa...
CVE-2020-3373HIGH8.6A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco...
CVE-2020-3352MEDIUM5.5A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker...
CVE-2020-3317HIGH7.5A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthen...
CVE-2020-3304HIGH8.6A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (F...
CVE-2020-3299MEDIUM5.8Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticate...
CVE-2020-17381HIGH7.3An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installa...
CVE-2020-15240CRITICAL9.1omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_...
CVE-2020-7750CRITICAL9.6This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not e...
CVE-2020-5651HIGH8.8SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQ...
CVE-2020-5650MEDIUM6.1Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arb...
CVE-2020-27613HIGH8.4The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which al...
CVE-2020-27612MEDIUM4.3Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information ...
CVE-2020-27611HIGH7.3BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
CVE-2020-27610HIGH7.5The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external inte...
CVE-2020-27609MEDIUM5.3BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. ...
CVE-2020-27608MEDIUM6.1In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, w...
CVE-2020-27607MEDIUM6.5In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop acce...
CVE-2020-27606MEDIUM5.3BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now