2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24056HIGH7.5A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31,...
CVE-2020-24055CRITICAL9.8Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service im...
CVE-2020-24054CRITICAL9.8The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that...
CVE-2020-24053HIGH7.5Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidential...
CVE-2020-24052CRITICAL9.1Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unaut...
CVE-2020-24051CRITICAL9.8The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol,...
CVE-2020-20634MEDIUM6.5Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exp...
CVE-2020-10290MEDIUM6.8Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restr...
CVE-2020-9246MEDIUM6.5FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and informatio...
CVE-2020-9104MEDIUM4.3HUAWEI P30 smartphones with Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1.0.123(C432E22R2P5),...
CVE-2020-9096MEDIUM5.5HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. S...
CVE-2020-9095MEDIUM5.5HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow vulnerability. Some...
CVE-2020-24585MEDIUM5.3An issue was discovered in the DTLS handshake implementation in wolfSSL before 4.5.0. Clear DTLS application_data messag...
CVE-2020-15309HIGH7An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a ca...
CVE-2020-12457HIGH7.5An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for...
CVE-2020-5774HIGH7.1Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios...
CVE-2020-3976MEDIUM5.3VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication serv...
CVE-2020-16241LOW2.1Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unaut...
CVE-2020-16239MEDIUM4.9When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficie...
CVE-2020-16237LOW2.1Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that...
CVE-2020-14518MEDIUM5.3Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.
CVE-2020-7710CRITICAL9.8This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host m...
CVE-2020-7310MEDIUM6.9Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 all...
CVE-2020-15070HIGH8.8Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres...
CVE-2020-14215HIGH7.5Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrato...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now