2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-13638CRITICAL9.8lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account cr...
CVE-2020-12338CRITICAL9.8Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user t...
CVE-2020-24719CRITICAL9.8Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by...
CVE-2020-13877CRITICAL9.8SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and...
CVE-2020-13774CRITICAL9.9An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an aut...
CVE-2020-12315CRITICAL9.8Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalati...
CVE-2020-8752CRITICAL9.8Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.7...
CVE-2020-8747CRITICAL9.1Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may al...
CVE-2020-7472CRITICAL9.8An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8...
CVE-2020-28271CRITICAL9.8Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service...
CVE-2020-28270CRITICAL9.8Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a ...
CVE-2020-28269CRITICAL9.8Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service a...
CVE-2020-27481CRITICAL9.8An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_no...
CVE-2020-7770CRITICAL9.8This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, ...
CVE-2020-3639CRITICAL9.8u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cyc...
CVE-2020-11196CRITICAL9.8u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Sn...
CVE-2020-11193CRITICAL9.8u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snap...
CVE-2020-11184CRITICAL9.8u'Possible buffer overflow will occur in video while parsing mp4 clip with crafted esds atom size.' in Snapdragon Auto, ...
CVE-2020-11168CRITICAL9.8u'Null-pointer dereference can occur while accessing data buffer beyond its size that leads to access the buffer beyond ...
CVE-2020-7769CRITICAL9.8This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary comm...
CVE-2020-5426CRITICAL9.8Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a ...
CVE-2020-7768CRITICAL9.8The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPac...
CVE-2020-17051CRITICAL9.8Windows Network File System Remote Code Execution Vulnerability
CVE-2020-26824CRITICAL10SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o...
CVE-2020-26823CRITICAL10SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now