2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14158CRITICAL9.1The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity ...
CVE-2020-12620HIGH7.8Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection...
CVE-2020-8222MEDIUM6.8A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the admi...
CVE-2020-8221MEDIUM4.9A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbi...
CVE-2020-8220MEDIUM6.5A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform...
CVE-2020-8219HIGH7.2An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change t...
CVE-2020-8218HIGH7.2A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform...
CVE-2020-8217MEDIUM5.4A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used f...
CVE-2020-8216MEDIUM4.3An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to ...
CVE-2020-8213MEDIUM5.3An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attacke...
CVE-2020-8206HIGH8.1An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users prim...
CVE-2020-8204MEDIUM6.1A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
CVE-2020-8202MEDIUM5.3Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when ...
CVE-2020-8192MEDIUM6.5A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger reso...
CVE-2020-4186MEDIUM5.3IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in furt...
CVE-2020-4185HIGH7.5IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2020-14309MEDIUM6.7There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link wi...
CVE-2020-10713HIGH8.2A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB veri...
CVE-2020-3701HIGH7.8Use after free issue while processing error notification from camx driver due to not properly releasing the sequence dat...
CVE-2020-3700HIGH7.5Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi dri...
CVE-2020-3699CRITICAL9.8Possible out of bound access while processing assoc response from host due to improper length check before copying into ...
CVE-2020-3698CRITICAL9.8Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response f...
CVE-2020-3688CRITICAL9.8Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapd...
CVE-2020-3671CRITICAL9.8Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compu...
CVE-2020-7699CRITICAL9.8This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP r...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now