2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12001CRITICAL9.8FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio...
CVE-2020-11999HIGH8.1FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio...
CVE-2020-11969CRITICAL9.8If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter...
CVE-2020-14159HIGH8.8By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands a...
CVE-2020-13652MEDIUM6.1An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1...
CVE-2020-13651HIGH7.8An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It all...
CVE-2020-13650HIGH7.5An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to ...
CVE-2020-14156HIGH8.8user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has str...
CVE-2020-14149HIGH7.5In uftpd before 2.12, handle_CWD in ftpcmd.c mishandled the path provided by the user, causing a NULL pointer dereferenc...
CVE-2020-14148HIGH7.5The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the...
CVE-2020-14147HIGH7.7An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with...
CVE-2020-14155MEDIUM5.3libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
CVE-2020-14154MEDIUM4.8Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an e...
CVE-2020-14153HIGH7.1In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers...
CVE-2020-14152HIGH7.1In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use se...
CVE-2020-14151Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11813. Reason: This candidate is a duplicate of ...
CVE-2020-14150MEDIUM5.5GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if ...
CVE-2020-14034CRITICAL9.8An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c ha...
CVE-2020-14033CRITICAL9.8An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plu...
CVE-2020-9076MEDIUM6.8HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier t...
CVE-2020-3961HIGH7.8VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permissio...
CVE-2020-14054CRITICAL9.8SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows r...
CVE-2020-13999MEDIUM5.5ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial ...
CVE-2020-13150HIGH7.8D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart...
CVE-2020-9427MEDIUM5OX Guard 2.10.3 and earlier allows SSRF.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now