2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-16846CRITICAL9.8An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien...
CVE-2020-28250CRITICAL9.8Cellinx NVT Web Server 5.0.0.014b.test 2019-09-05 allows a remote user to run commands as root via SetFileContent.cgi be...
CVE-2020-5648CRITICAL9.8Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl...
CVE-2020-5647CRITICAL9.8Improper access control vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT14...
CVE-2020-5644CRITICAL9.8Buffer overflow vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE...
CVE-2020-17510CRITICAL9.8Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentica...
CVE-2020-12145CRITICAL9.8Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API...
CVE-2020-27955CRITICAL9.8Git LFS 2.12.0 allows Remote Code Execution.
CVE-2020-15952CRITICAL9Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permi...
CVE-2020-7128CRITICAL9.8A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Pri...
CVE-2020-27689CRITICAL9.8The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credential...
CVE-2020-22274CRITICAL9.8JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
CVE-2020-26167CRITICAL9.8In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any acco...
CVE-2020-22276CRITICAL9.8WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
CVE-2020-2301CRITICAL9.8Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a succes...
CVE-2020-2300CRITICAL9.8Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, wh...
CVE-2020-2299CRITICAL9.8Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as t...
CVE-2020-1909CRITICAL9.8A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.2...
CVE-2020-16011CRITICAL9.6Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromi...
CVE-2020-16010CRITICAL9.6Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromi...
CVE-2020-15999CRITICAL9.6Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi...
CVE-2020-15993CRITICAL9.8Use after free in printing in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap ...
CVE-2020-5656CRITICAL9.8Improper access control vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 Ether...
CVE-2020-5653CRITICAL9.8Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP N...
CVE-2020-28039CRITICAL9.1is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not p...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now