2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5131HIGH7.8SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite...
CVE-2020-5130MEDIUM5.3SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper va...
CVE-2020-15497MEDIUM6.1jcore/portal/ajaxPortal.jsp in Jalios JCMS 10.0.2 build-20200224104759 allows XSS via the types parameter. Note: It is a...
CVE-2020-7826CRITICAL9.8EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be ...
CVE-2020-7825CRITICAL9.8A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05...
CVE-2020-15807MEDIUM6.5GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.
CVE-2020-15586MEDIUM5.9Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.Rev...
CVE-2020-14928MEDIUM5.9evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server send...
CVE-2020-14039MEDIUM5.3In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU re...
CVE-2020-14001CRITICAL9.8The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows ...
CVE-2020-4464HIGH8.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary c...
CVE-2020-7696MEDIUM5.3This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "...
CVE-2020-7684CRITICAL9.8This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
CVE-2020-15803MEDIUM6.1Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stor...
CVE-2020-15801CRITICAL9.8In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from ar...
CVE-2020-9688HIGH7.8Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to a...
CVE-2020-9682CRITICAL9.8Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful...
CVE-2020-9673HIGH7.8Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll searc...
CVE-2020-9672HIGH7.8Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll searc...
CVE-2020-9671CRITICAL9.8Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Succe...
CVE-2020-9670CRITICAL9.8Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful...
CVE-2020-9669CRITICAL9.8Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Succ...
CVE-2020-9650HIGH7.8Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l...
CVE-2020-9649MEDIUM5.5Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could le...
CVE-2020-9646HIGH7.8Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now