2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3266 | HIGH | 7.8 | 0.6% | Mar 19, 2020 | A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbi... |
| CVE-2020-3265 | HIGH | 7.8 | 0.4% | Mar 19, 2020 | A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to ... |
| CVE-2020-3264 | HIGH | 7.1 | 0.7% | Mar 19, 2020 | A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflo... |
| CVE-2020-1705 | HIGH | 7 | 0.3% | Mar 19, 2020 | A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an i... |
| CVE-2020-10678 | HIGH | 8.8 | 1.0% | Mar 19, 2020 | In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an... |
| CVE-2020-4205 | MEDIUM | 6.3 | 0.5% | Mar 19, 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, a... |
| CVE-2020-4203 | MEDIUM | 4.9 | 1.3% | Mar 19, 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privile... |
| CVE-2020-10675 | HIGH | 7.5 | 2.5% | Mar 19, 2020 | The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via... |
| CVE-2020-10648 | HIGH | 7.8 | 1.3% | Mar 19, 2020 | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images ... |
| CVE-2020-9423 | CRITICAL | 9.8 | 4.9% | Mar 18, 2020 | LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of ... |
| CVE-2020-10674 | CRITICAL | 9.8 | 1.3% | Mar 18, 2020 | PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argumen... |
| CVE-2020-10673 | HIGH | 8.8 | 8.0% | Mar 18, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-10672 | HIGH | 8.8 | 3.1% | Mar 18, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-10365 | MEDIUM | 6.5 | 1.3% | Mar 18, 2020 | LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the datab... |
| CVE-2020-7258 | MEDIUM | 4.8 | 0.5% | Mar 18, 2020 | Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update all... |
| CVE-2020-7256 | MEDIUM | 4.8 | 0.5% | Mar 18, 2020 | Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update all... |
| CVE-2020-10665 | MEDIUM | 6.7 | 1.4% | Mar 18, 2020 | Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnost... |
| CVE-2020-9326 | HIGH | 7.5 | 1.0% | Mar 18, 2020 | BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 ... |
| CVE-2020-9325 | HIGH | 7.5 | 1.8% | Mar 18, 2020 | Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download. |
| CVE-2020-9324 | HIGH | 7.5 | 1.4% | Mar 18, 2020 | Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC. |
| CVE-2020-9323 | MEDIUM | 5.3 | 1.6% | Mar 18, 2020 | Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx. |
| CVE-2020-6976 | MEDIUM | 5.5 | 0.8% | Mar 18, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited wh... |
| CVE-2020-4199 | MEDIUM | 4.3 | 0.5% | Mar 18, 2020 | IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute ma... |
| CVE-2020-9443 | MEDIUM | 6.1 | 0.6% | Mar 18, 2020 | Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be expl... |
| CVE-2020-7002 | HIGH | 7.8 | 1.1% | Mar 18, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be explo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now