2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15702HIGH7TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code....
CVE-2020-15701MEDIUM5.5An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of ...
CVE-2020-15136MEDIUM6.5In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV r...
CVE-2020-15114HIGH7.7In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery a...
CVE-2020-11937MEDIUM5.5In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The...
CVE-2020-15115HIGH7.5etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short pass...
CVE-2020-16229HIGH7.8Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper...
CVE-2020-16217HIGH7.8Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing speciall...
CVE-2020-16215HIGH7.8Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper...
CVE-2020-16213HIGH7.8Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper...
CVE-2020-16211MEDIUM5.5Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by p...
CVE-2020-16207HIGH7.8Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may b...
CVE-2020-13793CRITICAL9.8Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.
CVE-2020-12441CRITICAL9.8Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parse...
CVE-2020-16845HIGH7.5Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary...
CVE-2020-7817HIGH7.8MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a...
CVE-2020-7460HIGH7In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 1...
CVE-2020-7459MEDIUM6.8In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 1...
CVE-2020-13365HIGH8.8Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocu...
CVE-2020-13364HIGH8.8A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, ...
CVE-2020-7361HIGH8.8The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' co...
CVE-2020-7357CRITICAL9.9Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This ca...
CVE-2020-7356CRITICAL9.8CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_s...
CVE-2020-7352HIGH8.8The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to th...
CVE-2020-9036MEDIUM6.1Jeedom through 4.0.38 allows XSS.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now