2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-17463CRITICAL9.8FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
CVE-2020-4589CRITICAL9.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the s...
CVE-2020-16137CRITICAL9.8A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to re...
CVE-2020-8904CRITICAL9.6An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the eca...
CVE-2020-12107CRITICAL9.8The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full cont...
CVE-2020-12106CRITICAL9.8The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to severa...
CVE-2020-5415CRITICAL10Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to ide...
CVE-2020-17506CRITICAL9.8Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p...
CVE-2020-17446CRITICAL9.8asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database c...
CVE-2020-6294CRITICAL9.1Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any ...
CVE-2020-6284CRITICAL9SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script conten...
CVE-2020-17496CRITICAL9.8vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe...
CVE-2020-6932CRITICAL9.8An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Softwa...
CVE-2020-0260CRITICAL9.1There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID:...
CVE-2020-0253CRITICAL9.8There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-1526473...
CVE-2020-0252CRITICAL9.8There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-1522368...
CVE-2020-17466CRITICAL9.8Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redir...
CVE-2020-17368CRITICAL9.8Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may ...
CVE-2020-11552CRITICAL9.8An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not ...
CVE-2020-14324CRITICAL9.1A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS...
CVE-2020-14325CRITICAL9.1Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious at...
CVE-2020-17479CRITICAL9.8jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
CVE-2020-9529CRITICAL9.8Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions ...
CVE-2020-9527CRITICAL9.8Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many...
CVE-2020-13292CRITICAL9.6In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Fl...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now