2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3297CRITICAL9.8A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches cou...
CVE-2020-5238MEDIUM6.5The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs....
CVE-2020-15500MEDIUM6.1An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected u...
CVE-2020-15490CRITICAL9.8An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exi...
CVE-2020-15489CRITICAL9.8An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulne...
CVE-2020-14196MEDIUM5.3In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal we...
CVE-2020-7688HIGH7.8The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
CVE-2020-14057CRITICAL9.8Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read...
CVE-2020-14056CRITICAL9.8Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of th...
CVE-2020-14055MEDIUM6.1Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insuff...
CVE-2020-13619CRITICAL9.8php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
CVE-2020-6089HIGH7.8An exploitable code execution vulnerability exists in the ANI file format parser of Leadtools 20. A specially crafted AN...
CVE-2020-2500MEDIUM6.5This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers...
CVE-2020-12498HIGH7.8mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds ...
CVE-2020-12497HIGH7.8PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-bas...
CVE-2020-8663HIGH7.5Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many conne...
CVE-2020-5908MEDIUM5.5In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in ...
CVE-2020-5907HIGH7.2In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorize...
CVE-2020-5906HIGH8.1In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the acces...
CVE-2020-5905MEDIUM4.3In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize ...
CVE-2020-5904HIGH8.8In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSR...
CVE-2020-5903MEDIUM6.1In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vuln...
CVE-2020-5902CRITICAL9.8In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic ...
CVE-2020-5901CRITICAL9.6In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. ...
CVE-2020-5899HIGH7.8In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the dat...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now