2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7301MEDIUM4.6Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticat...
CVE-2020-7300MEDIUM6.3Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authentic...
CVE-2020-17450MEDIUM6.1PHP-Fusion 9.03 allows XSS on the preview page.
CVE-2020-17449MEDIUM5.4PHP-Fusion 9.03 allows XSS via the error_log file.
CVE-2020-17362MEDIUM6.1search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
CVE-2020-15868HIGH7.5Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
CVE-2020-15596MEDIUM6.7The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attacker...
CVE-2020-16186Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-16139HIGH7.5A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the de...
CVE-2020-16138HIGH7.5A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remot...
CVE-2020-16137CRITICAL9.8A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to re...
CVE-2020-8905MEDIUM6.5A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should no...
CVE-2020-8904CRITICAL9.6An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the eca...
CVE-2020-12107CRITICAL9.8The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full cont...
CVE-2020-12106CRITICAL9.8The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to severa...
CVE-2020-7374HIGH7.8Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validat...
CVE-2020-17507MEDIUM5.3An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmha...
CVE-2020-17361MEDIUM5.5An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h returns silentl...
CVE-2020-17360HIGH7.8An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multip...
CVE-2020-6653LOW3.9Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or re...
CVE-2020-5415CRITICAL10Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to ide...
CVE-2020-2035LOW3When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering...
CVE-2020-17506CRITICAL9.8Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p...
CVE-2020-17505HIGH8.8Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter i...
CVE-2020-15137MEDIUM5.9All versions of HoRNDIS are affected by an integer overflow in the RNDIS packet parsing routines. A malicious USB device...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now