2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15709MEDIUM5.5Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (p...
CVE-2020-24987CRITICAL9.8Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution ...
CVE-2020-24986HIGH7.2Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File ...
CVE-2020-24981MEDIUM5.3An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an...
CVE-2020-24963MEDIUM5.4An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
CVE-2020-24659HIGH7.5An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if ...
CVE-2020-14008HIGH7.2Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in...
CVE-2020-7299MEDIUM4.1Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) p...
CVE-2020-4702MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2020-4632MEDIUM6.5IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted ...
CVE-2020-4545HIGH7.8IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loadi...
CVE-2020-7119MEDIUM4.9A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier fir...
CVE-2020-7730CRITICAL9.8The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.
CVE-2020-25023CRITICAL9.8An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds ac...
CVE-2020-25022CRITICAL9.8An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds...
CVE-2020-25021CRITICAL9.8An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds acc...
CVE-2020-23834HIGH7.8Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to esca...
CVE-2020-12248HIGH8.8In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a he...
CVE-2020-12247HIGH7.1In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information fr...
CVE-2020-11493HIGH8.1In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information ab...
CVE-2020-3547MEDIUM6.5A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA)...
CVE-2020-3546MEDIUM5.3A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA)...
CVE-2020-3545MEDIUM6.7A vulnerability in Cisco FXOS Software could allow an authenticated, local attacker with administrative credentials to c...
CVE-2020-3542MEDIUM5.3A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeti...
CVE-2020-3541MEDIUM4.4A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop A...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now