2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-7127CRITICAL9.8A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Pri...
CVE-2020-7124CRITICAL9.8A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
CVE-2020-18766CRITICAL9.6A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.
CVE-2020-27678CRITICAL9.8An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and Sm...
CVE-2020-25483CRITICAL9.8An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an atta...
CVE-2020-25466CRITICAL9.8A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on ...
CVE-2020-15684CRITICAL9.8Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corru...
CVE-2020-15683CRITICAL9.8Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of...
CVE-2020-9920CRITICAL9.1A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Cat...
CVE-2020-9906CRITICAL9.1A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6,...
CVE-2020-27664CRITICAL9.8admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
CVE-2020-9898CRITICAL9.8This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10....
CVE-2020-9868CRITICAL9.1A certificate validation issue existed when processing administrator added certificates. This issue was addressed with i...
CVE-2020-15906CRITICAL9.8tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
CVE-2020-27195CRITICAL9.1HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using eithe...
CVE-2020-27619CRITICAL9.8In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via H...
CVE-2020-27615CRITICAL9.8The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa...
CVE-2020-15240CRITICAL9.1omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_...
CVE-2020-7750CRITICAL9.6This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not e...
CVE-2020-27605CRITICAL9.8BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject ...
CVE-2020-14882CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions...
CVE-2020-14876CRITICAL9.1Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface). Supported v...
CVE-2020-14875CRITICAL9.1Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supporte...
CVE-2020-14871CRITICAL10Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve...
CVE-2020-14859CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now