2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-15929CRITICAL9.8In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow ...
CVE-2020-28991CRITICAL9.8Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also...
CVE-2020-4006CRITICAL9.1VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command i...
CVE-2020-28984CRITICAL9.8prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, displ...
CVE-2020-28360CRITICAL9.8Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in ind...
CVE-2020-28864CRITICAL9.8Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspe...
CVE-2020-6939CRITICAL9.8Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users...
CVE-2020-4854CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key...
CVE-2020-25189CRITICAL9.8The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to...
CVE-2020-28877CRITICAL9.8Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, i...
CVE-2020-25839CRITICAL9.8NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability i...
CVE-2020-7561CRITICAL9.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and olde...
CVE-2020-28212CRITICAL9.8A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxur...
CVE-2020-28951CRITICAL9.8libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package nam...
CVE-2020-11831CRITICAL9.8OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovo...
CVE-2020-11830CRITICAL9.8QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2....
CVE-2020-11829CRITICAL9.8Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros....
CVE-2020-3586CRITICAL9.8A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remo...
CVE-2020-3531CRITICAL9.8A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacke...
CVE-2020-3470CRITICAL9.8Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthentic...
CVE-2020-3419CRITICAL9.1A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker ...
CVE-2020-28578CRITICAL9.8A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote a...
CVE-2020-26097CRITICAL9.8The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root ac...
CVE-2020-6016CRITICAL9.8Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in ...
CVE-2020-28183CRITICAL9.8SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to proce...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now