2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9523HIGH8.8Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting ...
CVE-2020-4277HIGH7.5IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an att...
CVE-2020-11875HIGH7.8An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK ke...
CVE-2020-11874HIGH7.5An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory ...
CVE-2020-11873CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer ove...
CVE-2020-11793HIGH8.8A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allow...
CVE-2020-10947HIGH8.8Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
CVE-2020-10813HIGH7.5A buffer overflow vulnerability in FTPDMIN 0.96 allows attackers to crash the server via a crafted packet.
CVE-2020-10377CRITICAL9.8A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated att...
CVE-2020-10211CRITICAL9.8A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthent...
CVE-2020-11872HIGH7.5The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests bef...
CVE-2020-11868HIGH7.5ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronizatio...
CVE-2020-5294MEDIUM5.4PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is ...
CVE-2020-5273MEDIUM5.4In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fix...
CVE-2020-5266MEDIUM5.4In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list blo...
CVE-2020-7486HIGH7.5**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in...
CVE-2020-7485CRITICAL9.8**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier c...
CVE-2020-7484HIGH7.5**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of servi...
CVE-2020-7483HIGH7.5**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the '...
CVE-2020-7224CRITICAL9.8The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered...
CVE-2020-7114CRITICAL9.8A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, ...
CVE-2020-7113MEDIUM4.9A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to inte...
CVE-2020-7111HIGH7.2A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Co...
CVE-2020-7110MEDIUM4.8ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administr...
CVE-2020-2180HIGH8.8Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now