2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7315MEDIUM6.7DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code...
CVE-2020-7314HIGH7.8Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAf...
CVE-2020-7312HIGH7.8DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local u...
CVE-2020-7311HIGH7Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users t...
CVE-2020-24552HIGH7.2Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation,...
CVE-2020-25220HIGH7.8The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because s...
CVE-2020-24655MEDIUM5.1A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to pote...
CVE-2020-15173CRITICAL9.8In ACCEL-PPP (an implementation of PPTP/PPPoE/L2TP/SSTP), there is a buffer overflow when receiving an l2tp control pack...
CVE-2020-25219HIGH7.5url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion ...
CVE-2020-15903CRITICAL9.8An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran ...
CVE-2020-24916CRITICAL9.8CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
CVE-2020-24379CRITICAL9.8WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
CVE-2020-1913HIGH8.1An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c0...
CVE-2020-1912HIGH8.1An out-of-bounds read/write vulnerability when executing lazily compiled inner generator functions in Facebook Hermes pr...
CVE-2020-15791MEDIUM6.5A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All ver...
CVE-2020-15790MEDIUM5.3A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner,...
CVE-2020-15789HIGH8.1A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cro...
CVE-2020-15788MEDIUM6.1A vulnerability has been identified in Polarion Subversion Webclient (All versions). The Polarion subversion web applica...
CVE-2020-15787CRITICAL9.8A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insuff...
CVE-2020-15786CRITICAL9.8A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V...
CVE-2020-15785MEDIUM5.3A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authe...
CVE-2020-15784MEDIUM5.3A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive inform...
CVE-2020-10056HIGH7.8A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the ...
CVE-2020-10051HIGH7.8A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the ...
CVE-2020-10050HIGH7.8A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now