2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-16169CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 a...
CVE-2020-16167CRITICAL9.1Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remot...
CVE-2020-13376CRITICAL9SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted ...
CVE-2020-11984CRITICAL9.8Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
CVE-2020-8025CRITICAL9.3A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-S...
CVE-2020-13793CRITICAL9.8Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.
CVE-2020-12441CRITICAL9.8Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parse...
CVE-2020-7357CRITICAL9.9Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This ca...
CVE-2020-7356CRITICAL9.8CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_s...
CVE-2020-5609CRITICAL9.8Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, C...
CVE-2020-5608CRITICAL9.8CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, B...
CVE-2020-17353CRITICAL9.8scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restri...
CVE-2020-13921CRITICAL9.8**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the w...
CVE-2020-13151CRITICAL9.8Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)...
CVE-2020-4459CRITICAL9.8IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses ...
CVE-2020-5616CRITICAL9.8[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Cale...
CVE-2020-16272CRITICAL9.1The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, w...
CVE-2020-16271CRITICAL9.1The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows re...
CVE-2020-4377CRITICAL9.1IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML dat...
CVE-2020-5413CRITICAL9.8Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo...
CVE-2020-10731CRITICAL9.9A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SEL...
CVE-2020-3681CRITICAL9.8Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recov...
CVE-2020-3382CRITICAL9.8A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attac...
CVE-2020-3376CRITICAL9.8A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthentic...
CVE-2020-3375CRITICAL9.8A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer over...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now