2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-15866CRITICAL9.8mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrec...
CVE-2020-6103CRITICAL9.9An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64....
CVE-2020-6102CRITICAL9.9An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64....
CVE-2020-6101CRITICAL9.9An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64....
CVE-2020-6100CRITICAL9.9An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially...
CVE-2020-6871CRITICAL9.8The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the a...
CVE-2020-15123CRITICAL9.3In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the co...
CVE-2020-15121CRITICAL9.6In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the p...
CVE-2020-14494CRITICAL9.8OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide ...
CVE-2020-14485CRITICAL9.8OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted...
CVE-2020-14484CRITICAL9.8OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, whi...
CVE-2020-7206CRITICAL9.8HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.
CVE-2020-5759CRITICAL9.8Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authen...
CVE-2020-5757CRITICAL9.8Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authe...
CVE-2020-0231CRITICAL9.8There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid I...
CVE-2020-0230CRITICAL9.8There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid I...
CVE-2020-0225CRITICAL9.8In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to...
CVE-2020-0224CRITICAL9.8In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could...
CVE-2020-1654CRITICAL9.8On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a m...
CVE-2020-1652CRITICAL9.8OpenNMS is accessible via port 9443
CVE-2020-1647CRITICAL9.8On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free ...
CVE-2020-7826CRITICAL9.8EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be ...
CVE-2020-7825CRITICAL9.8A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05...
CVE-2020-14001CRITICAL9.8The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows ...
CVE-2020-7684CRITICAL9.8This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now