2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3537MEDIUM5.7A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sen...
CVE-2020-3530HIGH8.4A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate...
CVE-2020-3498MEDIUM6.5A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive infor...
CVE-2020-3495HIGH8.8A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The...
CVE-2020-3478HIGH8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, re...
CVE-2020-3473HIGH7.8A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate...
CVE-2020-3453MEDIUM6.8Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow ...
CVE-2020-3451MEDIUM4.7Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow ...
CVE-2020-3430HIGH8.8A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated...
CVE-2020-3365MEDIUM6.5A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an auth...
CVE-2020-1911CRITICAL9.8A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains i...
CVE-2020-24941HIGH7.5An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some sit...
CVE-2020-24940HIGH7.5An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in...
CVE-2020-24980Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-24979Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-24978CRITICAL9.8In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca00...
CVE-2020-24977MEDIUM6.5GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entiti...
CVE-2020-24999HIGH7.8There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by send...
CVE-2020-24996HIGH7.8There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can ...
CVE-2020-25006CRITICAL9.8Heybbs v1.2 has a SQL injection vulnerability in login.php file via the username parameter which may allow a remote atta...
CVE-2020-25005CRITICAL9.8Heybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to ...
CVE-2020-25004CRITICAL9.8Heybbs v1.2 has a SQL injection vulnerability in user.php file via the ID parameter which may allow a remote attacker to...
CVE-2020-1894HIGH8.8A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, Whats...
CVE-2020-1891CRITICAL9.8A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android ...
CVE-2020-1890HIGH7.5A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 coul...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now