2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-15715CRITICAL9.9rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error i...
CVE-2020-16088CRITICAL9.8iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for chec...
CVE-2020-12460CRITICAL9.8OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse ...
CVE-2020-12812CRITICAL9.8An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a us...
CVE-2020-15860CRITICAL9.9Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an ...
CVE-2020-15922CRITICAL9.8There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)...
CVE-2020-15921CRITICAL9.8Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric...
CVE-2020-15920CRITICAL9.8There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi...
CVE-2020-11624CRITICAL9.8An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Ind...
CVE-2020-15492CRITICAL9.8An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we...
CVE-2020-15477CRITICAL9.8The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters i...
CVE-2020-15391CRITICAL9.8The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authe...
CVE-2020-15917CRITICAL9.8common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
CVE-2020-15916CRITICAL9.8goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system...
CVE-2020-10921CRITICAL9.8This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware versio...
CVE-2020-10920CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmwar...
CVE-2020-10917CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.4...
CVE-2020-4385CRITICAL9.8IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which...
CVE-2020-9664CRITICAL9.8Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exp...
CVE-2020-15893CRITICAL9.8An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled b...
CVE-2020-15892CRITICAL9.8An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login a...
CVE-2020-6522CRITICAL9.6Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attac...
CVE-2020-6509CRITICAL9.6Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install...
CVE-2020-6505CRITICAL9.6Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sand...
CVE-2020-15889CRITICAL9.8Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now