2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15073MEDIUM5.4An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section v...
CVE-2020-15072HIGH8.8An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Admin...
CVE-2020-2034HIGH8.1An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacke...
CVE-2020-2031MEDIUM4.9An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated ad...
CVE-2020-2030HIGH7.2An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to exe...
CVE-2020-1982MEDIUM4.8Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryp...
CVE-2020-6938HIGH7.5A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26,...
CVE-2020-5839HIGH7.5Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is ...
CVE-2020-11994HIGH7.5Server-Side Template Injection and arbitrary file disclosure on Camel templating components
CVE-2020-14476Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-7140MEDIUM6.1A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a ...
CVE-2020-5764HIGH8.8MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is usin...
CVE-2020-3973HIGH8.8The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious act...
CVE-2020-11849CRITICAL9.8Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prio...
CVE-2020-3931CRITICAL9.8Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute ar...
CVE-2020-15600MEDIUM6.5An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
CVE-2020-8916MEDIUM5.5A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an e...
CVE-2020-15599MEDIUM6.1Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
CVE-2020-8521CRITICAL9.8SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with a...
CVE-2020-8520CRITICAL9.8SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with aja...
CVE-2020-8519CRITICAL9.8SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php...
CVE-2020-15008HIGH7.5A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the pr...
CVE-2020-12821CRITICAL9.8Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
CVE-2020-12736HIGH7.2Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an...
CVE-2020-15095MEDIUM4.4Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The C...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now