2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3460MEDIUM6.1A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2020-3386HIGH8.8A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remot...
CVE-2020-3384HIGH8.2A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated,...
CVE-2020-3383HIGH8.8A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote ...
CVE-2020-3382CRITICAL9.8A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attac...
CVE-2020-3377HIGH8.8A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticat...
CVE-2020-3376CRITICAL9.8A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthentic...
CVE-2020-3375CRITICAL9.8A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer over...
CVE-2020-3374CRITICAL9.9A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem...
CVE-2020-16166LOW3.7The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information a...
CVE-2020-16165CRITICAL9.8The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to t...
CVE-2020-7205MEDIUM6.7A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and H...
CVE-2020-16164HIGH7.4An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypas...
CVE-2020-16163CRITICAL9.1An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lac...
CVE-2020-16162HIGH7.5An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL pr...
CVE-2020-15129MEDIUM4.7In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik...
CVE-2020-16157MEDIUM5.4A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
CVE-2020-15131HIGH7.5In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation o...
CVE-2020-15130HIGH7.5In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for t...
CVE-2020-7829HIGH7.8DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malform...
CVE-2020-7828HIGH7.8DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malform...
CVE-2020-7827HIGH7.8DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed sp...
CVE-2020-15957HIGH7.5An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). ...
CVE-2020-15511MEDIUM5.3HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when ...
CVE-2020-14162HIGH7.8An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core s...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now