2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12835CRITICAL9.8An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an un...
CVE-2020-13226CRITICAL9.8WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibil...
CVE-2020-5579HIGH7.2SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to...
CVE-2020-13225MEDIUM4.8phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the Us...
CVE-2020-9753CRITICAL9.1Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
CVE-2020-12034HIGH8.2Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterpris...
CVE-2020-7139HIGH8.1Potential remote access security vulnerabilities have been identified with HPE Nimble Storage systems that could be expl...
CVE-2020-7138HIGH8.8Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could...
CVE-2020-7137MEDIUM6.7A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Fle...
CVE-2020-13164HIGH7.5In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in ...
CVE-2020-13163HIGH7.4em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle atta...
CVE-2020-12038MEDIUM5.5Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterpris...
CVE-2020-7656MEDIUM6.1jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re...
CVE-2020-2025HIGH8.8Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the ...
CVE-2020-2024MEDIUM6.5An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a m...
CVE-2020-13167CRITICAL9.8Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain...
CVE-2020-13166CRITICAL9.8The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod...
CVE-2020-11766HIGH8.8sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command...
CVE-2020-10724MEDIUM4.4A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for use...
CVE-2020-10723MEDIUM6.7A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on th...
CVE-2020-10722MEDIUM6.7A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_lo...
CVE-2020-11715CRITICAL9.8Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected produc...
CVE-2020-10995HIGH7.5PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An is...
CVE-2020-11807HIGH7.8Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user...
CVE-2020-10135MEDIUM5.4Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now