2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13901CRITICAL9.8An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-...
CVE-2020-13900HIGH7.5An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NUL...
CVE-2020-13899HIGH7.5An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in jan...
CVE-2020-13898HIGH7.5An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL...
CVE-2020-5363MEDIUM6.7Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed ...
CVE-2020-5362MEDIUM4.4Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability ...
CVE-2020-4043CRITICAL9.8phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading ...
CVE-2020-13238HIGH7.5Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthe...
CVE-2020-11622HIGH7.5A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below...
CVE-2020-10705HIGH7.5A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-con...
CVE-2020-13906HIGH7.8IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038eb7.
CVE-2020-13905HIGH8.8IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038ed4.
CVE-2020-13445HIGH8.8In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6...
CVE-2020-13444MEDIUM6.5Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack...
CVE-2020-13223HIGH7.5HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials....
CVE-2020-12757CRITICAL9.8HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly gener...
CVE-2020-2033MEDIUM5.3When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can di...
CVE-2020-2032HIGH7A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to ex...
CVE-2020-2029HIGH7.2An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to exec...
CVE-2020-2028HIGH7.2An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitra...
CVE-2020-2027HIGH7.2A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrato...
CVE-2020-2026HIGH8.8A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple cont...
CVE-2020-2023MEDIUM6.3Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can ...
CVE-2020-14012MEDIUM5.4scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker...
CVE-2020-14010MEDIUM6.1The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parame...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now