2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11701HIGH8.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonst...
CVE-2020-11694HIGH7.5In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed...
CVE-2020-11647HIGH7.5In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed i...
CVE-2020-9056MEDIUM5.4Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated a...
CVE-2020-6765HIGH7.2D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a suppo...
CVE-2020-5406MEDIUM6.5VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x vers...
CVE-2020-5330HIGH7.5Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 ...
CVE-2020-5303LOW3.7Tendermint before versions 0.33.3, 0.32.10, and 0.31.12 has a denial-of-service vulnerability. Tendermint does not limit...
CVE-2020-11002HIGH8.8dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template...
CVE-2020-1801MEDIUM5.5There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does ...
CVE-2020-11669MEDIUM5.5An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does n...
CVE-2020-4362HIGH8.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerabilit...
CVE-2020-3952CRITICAL9.8Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi...
CVE-2020-1802MEDIUM4.6There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently valida...
CVE-2020-8832MEDIUM5.5The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data struc...
CVE-2020-1633MEDIUM6.5Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Ju...
CVE-2020-8834MEDIUM6.5KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entr...
CVE-2020-11668HIGH7.1In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles i...
CVE-2020-8961CRITICAL9.8An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a w...
CVE-2020-7922MEDIUM6.5X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kube...
CVE-2020-1895HIGH7.8A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dim...
CVE-2020-5263MEDIUM4.9auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of...
CVE-2020-9500MEDIUM4.9Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the atta...
CVE-2020-9499HIGH7.2Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker ...
CVE-2020-10631CRITICAL9.8An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now