2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-29238HIGH7.5An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi...
CVE-2020-35524HIGH7.8A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A spec...
CVE-2020-35523HIGH7.8An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to in...
CVE-2020-28952HIGH7.5An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique S...
CVE-2020-27225HIGH7.8In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to t...
CVE-2020-27575HIGH8.8Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functio...
CVE-2020-27574HIGH8.8Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malic...
CVE-2020-4695HIGH7.5IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens ...
CVE-2020-23967HIGH7.8Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges ...
CVE-2020-28466HIGH7.5This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the ser...
CVE-2020-29030HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute maliciou...
CVE-2020-29020HIGH7.2Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI ...
CVE-2020-28502HIGH8.1This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are ...
CVE-2020-29032HIGH7.2Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated att...
CVE-2020-29134HIGH8.6The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all v...
CVE-2020-5148HIGH8.2SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing m...
CVE-2020-36255HIGH7.5An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0. The Branca implementation allows a...
CVE-2020-15938HIGH7.5When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 ...
CVE-2020-24036HIGH8.8PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote u...
CVE-2020-28597HIGH7.5A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting...
CVE-2020-13558HIGH8.8A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A sp...
CVE-2020-27779HIGH7.5A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an p...
CVE-2020-25647HIGH7.6A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very li...
CVE-2020-25632HIGH8.2A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a...
CVE-2020-14372HIGH7.5A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Sec...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now