2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15543CRITICAL9.8SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
CVE-2020-15542CRITICAL9.8SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
CVE-2020-15541CRITICAL9.8SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
CVE-2020-15540CRITICAL9.8We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.
CVE-2020-15539CRITICAL9.8SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.
CVE-2020-15538MEDIUM6.1XSS can occur in We-com Municipality portal CMS 2.1.x via the cerca/ search bar.
CVE-2020-15537MEDIUM6.1An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product...
CVE-2020-15536MEDIUM6.1An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can...
CVE-2020-15535MEDIUM6.1An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur ...
CVE-2020-15466HIGH7.5In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/pa...
CVE-2020-15530HIGH7.8An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM p...
CVE-2020-15529HIGH7.8An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a g...
CVE-2020-15528HIGH7.8An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or un...
CVE-2020-15523HIGH7.8In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan hors...
CVE-2020-7284HIGH7.8Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to ga...
CVE-2020-10282CRITICAL9.8The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization...
CVE-2020-10281HIGH7.5This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access ...
CVE-2020-7283HIGH8.8Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edi...
CVE-2020-7282MEDIUM6.3Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files t...
CVE-2020-7281MEDIUM6.3Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files...
CVE-2020-15518HIGH8.8VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, w...
CVE-2020-14173MEDIUM5.4The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject ...
CVE-2020-14172CRITICAL9.8This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templ...
CVE-2020-15469LOW2.3In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.
CVE-2020-8188HIGH8.8We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and U...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now