2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-35464CRITICAL9.8Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using ...
CVE-2020-35463CRITICAL9.8Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed usin...
CVE-2020-35462CRITICAL9.8Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using aff...
CVE-2020-29663CRITICAL9.1Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically b...
CVE-2020-27068CRITICAL9.8Product: AndroidVersions: Android kernelAndroid ID: A-127973231References: Upstream kernel
CVE-2020-4747CRITICAL9.8IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated C...
CVE-2020-28442CRITICAL9.8All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
CVE-2020-0456CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-0457CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-0455CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-25228CRITICAL9.8A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on ...
CVE-2020-20189CRITICAL9.8SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
CVE-2020-8257CRITICAL9.8Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-...
CVE-2020-25187CRITICAL9.8Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent...
CVE-2020-20184CRITICAL9.8GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting...
CVE-2020-20136CRITICAL9.8QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to inse...
CVE-2020-35338CRITICAL9.8The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier...
CVE-2020-25179CRITICAL9.8GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net...
CVE-2020-25175CRITICAL9.8GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net...
CVE-2020-35378CRITICAL9.8SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands ...
CVE-2020-14268CRITICAL9.8A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by a...
CVE-2020-14244CRITICAL9.8A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by ...
CVE-2020-29227CRITICAL9.8An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack...
CVE-2020-5639CRITICAL9.8Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitra...
CVE-2020-29563CRITICAL9.8An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vuln...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now