2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15645HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso...
CVE-2020-15644HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso...
CVE-2020-15643HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso...
CVE-2020-15642HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marve...
CVE-2020-15641HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConve...
CVE-2020-15640HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConve...
CVE-2020-15639CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso...
CVE-2020-7824MEDIUM6.5A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get admi...
CVE-2020-24622MEDIUM4.9In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
CVE-2020-16245CRITICAL9.8Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could...
CVE-2020-16197MEDIUM4.3An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that...
CVE-2020-24616HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-24609MEDIUM6.1TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the X...
CVE-2020-14042MEDIUM6.1** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and late...
CVE-2020-24614HIGH8.8Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitr...
CVE-2020-24242MEDIUM5.5In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.
CVE-2020-24241MEDIUM5.5In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.
CVE-2020-24240MEDIUM5.5GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is...
CVE-2020-14524CRITICAL9.8Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerab...
CVE-2020-14522HIGH7.5Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerab...
CVE-2020-14512HIGH7.5GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user...
CVE-2020-14510CRITICAL9.8GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unpriv...
CVE-2020-14508CRITICAL9.8GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attack...
CVE-2020-14500CRITICAL9.8Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.
CVE-2020-17386MEDIUM6.5Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user,...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now