2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11102MEDIUM5.6hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not val...
CVE-2020-9473MEDIUM6.6The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, a...
CVE-2020-7622CRITICAL9.8This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set t...
CVE-2020-1728MEDIUM5.4A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are ...
CVE-2020-8004HIGH7.5STMicroelectronics STM32F1 devices have Incorrect Access Control.
CVE-2020-7639MEDIUM5.3eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or ...
CVE-2020-7638MEDIUM5.3confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding ...
CVE-2020-7637MEDIUM5.3class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could ...
CVE-2020-7636CRITICAL9.8adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command fu...
CVE-2020-7635CRITICAL9.8compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha optio...
CVE-2020-7634CRITICAL9.8heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
CVE-2020-7633CRITICAL9.8apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via th...
CVE-2020-7632CRITICAL9.8node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options arg...
CVE-2020-7631CRITICAL9.8diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path arg...
CVE-2020-10267HIGH7.5Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or...
CVE-2020-10266HIGH8.1UR+ (Universal Robots+) is a platform of hardware and software component sellers, for Universal Robots robots. When inst...
CVE-2020-10265CRITICAL9.4Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Versi...
CVE-2020-10264HIGH8.8CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Da...
CVE-2020-11565MEDIUM6An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bou...
CVE-2020-11558CRITICAL9.8An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_c...
CVE-2020-11548CRITICAL9.8The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. T...
CVE-2020-11547MEDIUM5.3PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes runn...
CVE-2020-11542CRITICAL9.83xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication...
CVE-2020-11533MEDIUM5.5Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive info...
CVE-2020-11529MEDIUM6.1Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now