2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10629HIGH7.5WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker...
CVE-2020-10625CRITICAL9.8WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.
CVE-2020-10623MEDIUM6.5Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions...
CVE-2020-10619CRITICAL9.1An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) cont...
CVE-2020-10617HIGH7.5There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0....
CVE-2020-10603HIGH8.8WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system...
CVE-2020-11557HIGH7.5An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password va...
CVE-2020-11556MEDIUM5.4An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) a...
CVE-2020-11555HIGH7.5An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sen...
CVE-2020-11554HIGH7.5An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sen...
CVE-2020-11553HIGH8.8An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
CVE-2020-10621CRITICAL9.8Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).
CVE-2020-10551HIGH7.8QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to th...
CVE-2020-11656CRITICAL9.8In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause tha...
CVE-2020-11655HIGH7.5SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function...
CVE-2020-11653HIGH7.5An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occu...
CVE-2020-11650HIGH7.5An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a deni...
CVE-2020-2732MEDIUM6.8A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtu...
CVE-2020-8828HIGH8.8As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster o...
CVE-2020-8827HIGH7.5As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other...
CVE-2020-8826HIGH7.5As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, ...
CVE-2020-1885HIGH7.8Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows ...
CVE-2020-1639HIGH7.5When an attacker sends a specific crafted Ethernet Operation, Administration, and Maintenance (Ethernet OAM) packet to a...
CVE-2020-1638HIGH7.5The FPC (Flexible PIC Concentrator) of Juniper Networks Junos OS and Junos OS Evolved may restart after processing a spe...
CVE-2020-1637MEDIUM6.5A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to acces...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now