2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-13554HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD...
CVE-2020-35296HIGH7.5ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboar...
CVE-2020-10519HIGH8.8A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a...
CVE-2020-12528HIGH7.7An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improp...
CVE-2020-35662HIGH7.4In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not alway...
CVE-2020-28243HIGH7.8An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection vi...
CVE-2020-36079HIGH7.2Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacke...
CVE-2020-24686HIGH7.5The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leadin...
CVE-2020-28646HIGH7.8ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain dir...
CVE-2020-17162HIGH8.8Microsoft Windows Security Feature Bypass Vulnerability
CVE-2020-27543HIGH7.5The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP...
CVE-2020-8032HIGH7A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to esc...
CVE-2020-36254HIGH8.1scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
CVE-2020-11988HIGH8.2Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input valida...
CVE-2020-11987HIGH8.2Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPan...
CVE-2020-7836HIGH7.8VOICEYE WSActiveBridgeES versions prior to 2.1.0.3 contains a stack-based buffer overflow vulnerability caused by improp...
CVE-2020-7846HIGH8.8Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key....
CVE-2020-28599HIGH7.8A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-...
CVE-2020-28587HIGH7.8A specially crafted document can cause the document parser to copy data from a particular record type into a static-size...
CVE-2020-27782HIGH7.5A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an...
CVE-2020-25161HIGH8.8The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path...
CVE-2020-16243HIGH7.8Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. ...
CVE-2020-7847HIGH8The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can b...
CVE-2020-14359HIGH7.3A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an a...
CVE-2020-25690HIGH8.8An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certai...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now