2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-27519HIGH7.8Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The at...
CVE-2020-18032HIGH7.8Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to exe...
CVE-2020-22002HIGH7.5An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI...
CVE-2020-21997HIGH7.5Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vul...
CVE-2020-21992HIGH8.8Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. T...
CVE-2020-21990HIGH7.5Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vuln...
CVE-2020-36327HIGH8.8Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem ve...
CVE-2020-7038HIGH7.5A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an una...
CVE-2020-7037HIGH8.1An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an auth...
CVE-2020-22785HIGH7.5Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting rando...
CVE-2020-22784HIGH7.5In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retriev...
CVE-2020-22782HIGH7.5Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import end...
CVE-2020-22781HIGH7.5In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denia...
CVE-2020-7123HIGH7.8A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5...
CVE-2020-21996HIGH7.5AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to ca...
CVE-2020-18019HIGH7.5SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary c...
CVE-2020-22000HIGH8HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. ...
CVE-2020-21989HIGH8.8HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform...
CVE-2020-17517HIGH7.5The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The curren...
CVE-2020-36325HIGH7.5An issue was discovered in Jansson through 2.13.1. Due to a parsing error in json_loads, there's an out-of-bounds read-a...
CVE-2020-15078HIGH7.5OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on...
CVE-2020-7034HIGH8.8A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote...
CVE-2020-7385HIGH8.8By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the sa...
CVE-2020-36321HIGH7.5Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0....
CVE-2020-36320HIGH7.5Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now