2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3463MEDIUM6.1A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote att...
CVE-2020-3449MEDIUM4.3A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an un...
CVE-2020-3448MEDIUM5.8A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, rem...
CVE-2020-3447MEDIUM6.5A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content...
CVE-2020-3435MEDIUM5.5A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c...
CVE-2020-3434MEDIUM5.5A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c...
CVE-2020-3433HIGH7.8A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c...
CVE-2020-3413MEDIUM4.3A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote a...
CVE-2020-3412MEDIUM4.3A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote a...
CVE-2020-3411HIGH7.5A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive informat...
CVE-2020-3363HIGH8.6A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an u...
CVE-2020-3346MEDIUM6.1A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Mana...
CVE-2020-7704CRITICAL9.8The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
CVE-2020-24372HIGH7.5LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
CVE-2020-24371MEDIUM5.3lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation...
CVE-2020-24370MEDIUM5.3ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by get...
CVE-2020-24369HIGH7.5ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL p...
CVE-2020-24220HIGH8.8ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands ...
CVE-2020-24208CRITICAL9.8A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to...
CVE-2020-9241HIGH7Huawei 5G Mobile WiFi E6878-370 with versions of 10.0.3.1(H563SP1C00),10.0.3.1(H563SP21C233) have an improper authorizat...
CVE-2020-9237MEDIUM6.7Huawei smartphone Taurus-AL00B with versions earlier than 10.1.0.126(C00E125R5P3) have a user after free vulnerability. ...
CVE-2020-9233CRITICAL9.1FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to dele...
CVE-2020-8233HIGH8.8A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to ...
CVE-2020-8232MEDIUM6.5An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could ...
CVE-2020-8230MEDIUM5.5A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in fo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now