2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-7746CRITICAL9.8This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. Wh...
CVE-2020-11486CRITICAL9.8NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmwa...
CVE-2020-11483CRITICAL9.8NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior...
CVE-2020-27739CRITICAL9.8A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack ...
CVE-2020-16263CRITICAL9.1Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewe...
CVE-2020-16259CRITICAL9.8Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents ...
CVE-2020-16257CRITICAL9.8Winston 1.5.4 devices are vulnerable to command injection via the API.
CVE-2020-27976CRITICAL9.8osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter ...
CVE-2020-8239CRITICAL9.8A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation att...
CVE-2020-27956CRITICAL9.8An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the use...
CVE-2020-9866CRITICAL9.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.6, Security U...
CVE-2020-27160CRITICAL9.8Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digi...
CVE-2020-27159CRITICAL9.8Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validat...
CVE-2020-27158CRITICAL9.8Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My...
CVE-2020-25765CRITICAL9.8Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western ...
CVE-2020-12830CRITICAL9.8Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privile...
CVE-2020-27853CRITICAL9.8Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbi...
CVE-2020-11854CRITICAL9.8Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bri...
CVE-2020-10256CRITICAL9.8An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1...
CVE-2020-27183CRITICAL9.8A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to discl...
CVE-2020-27179CRITICAL9.8konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset to...
CVE-2020-27743CRITICAL9.8libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to ...
CVE-2020-26879CRITICAL9.8Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacke...
CVE-2020-15272CRITICAL9.6In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*)...
CVE-2020-7197CRITICAL9.8SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off nod...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now