2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3463 | MEDIUM | 6.1 | 0.8% | Aug 17, 2020 | A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote att... |
| CVE-2020-3449 | MEDIUM | 4.3 | 1.1% | Aug 17, 2020 | A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an un... |
| CVE-2020-3448 | MEDIUM | 5.8 | 1.1% | Aug 17, 2020 | A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, rem... |
| CVE-2020-3447 | MEDIUM | 6.5 | 0.7% | Aug 17, 2020 | A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content... |
| CVE-2020-3435 | MEDIUM | 5.5 | 0.3% | Aug 17, 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c... |
| CVE-2020-3434 | MEDIUM | 5.5 | 0.5% | Aug 17, 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c... |
| CVE-2020-3433 | HIGH | 7.8 | 10.0% | Aug 17, 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c... |
| CVE-2020-3413 | MEDIUM | 4.3 | 0.7% | Aug 17, 2020 | A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote a... |
| CVE-2020-3412 | MEDIUM | 4.3 | 0.7% | Aug 17, 2020 | A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote a... |
| CVE-2020-3411 | HIGH | 7.5 | 2.2% | Aug 17, 2020 | A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive informat... |
| CVE-2020-3363 | HIGH | 8.6 | 1.8% | Aug 17, 2020 | A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an u... |
| CVE-2020-3346 | MEDIUM | 6.1 | 0.8% | Aug 17, 2020 | A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Mana... |
| CVE-2020-7704 | CRITICAL | 9.8 | 2.7% | Aug 17, 2020 | The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor. |
| CVE-2020-24372 | HIGH | 7.5 | 1.5% | Aug 17, 2020 | LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c. |
| CVE-2020-24371 | MEDIUM | 5.3 | 1.8% | Aug 17, 2020 | lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation... |
| CVE-2020-24370 | MEDIUM | 5.3 | 3.9% | Aug 17, 2020 | ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by get... |
| CVE-2020-24369 | HIGH | 7.5 | 1.7% | Aug 17, 2020 | ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL p... |
| CVE-2020-24220 | HIGH | 8.8 | 2.4% | Aug 17, 2020 | ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands ... |
| CVE-2020-24208 | CRITICAL | 9.8 | 3.3% | Aug 17, 2020 | A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to... |
| CVE-2020-9241 | HIGH | 7 | 0.5% | Aug 17, 2020 | Huawei 5G Mobile WiFi E6878-370 with versions of 10.0.3.1(H563SP1C00),10.0.3.1(H563SP21C233) have an improper authorizat... |
| CVE-2020-9237 | MEDIUM | 6.7 | 0.2% | Aug 17, 2020 | Huawei smartphone Taurus-AL00B with versions earlier than 10.1.0.126(C00E125R5P3) have a user after free vulnerability. ... |
| CVE-2020-9233 | CRITICAL | 9.1 | 0.8% | Aug 17, 2020 | FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to dele... |
| CVE-2020-8233 | HIGH | 8.8 | 4.4% | Aug 17, 2020 | A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to ... |
| CVE-2020-8232 | MEDIUM | 6.5 | 1.7% | Aug 17, 2020 | An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could ... |
| CVE-2020-8230 | MEDIUM | 5.5 | 0.4% | Aug 17, 2020 | A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in fo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now