2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3266HIGH7.8A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbi...
CVE-2020-3265HIGH7.8A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to ...
CVE-2020-3264HIGH7.1A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflo...
CVE-2020-1705HIGH7A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an i...
CVE-2020-10678HIGH8.8In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an...
CVE-2020-4205MEDIUM6.3IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, a...
CVE-2020-4203MEDIUM4.9IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privile...
CVE-2020-10675HIGH7.5The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via...
CVE-2020-10648HIGH7.8Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images ...
CVE-2020-9423CRITICAL9.8LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of ...
CVE-2020-10674CRITICAL9.8PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argumen...
CVE-2020-10673HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-10672HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-10365MEDIUM6.5LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the datab...
CVE-2020-7258MEDIUM4.8Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update all...
CVE-2020-7256MEDIUM4.8Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update all...
CVE-2020-10665MEDIUM6.7Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnost...
CVE-2020-9326HIGH7.5BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 ...
CVE-2020-9325HIGH7.5Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.
CVE-2020-9324HIGH7.5Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.
CVE-2020-9323MEDIUM5.3Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.
CVE-2020-6976MEDIUM5.5Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited wh...
CVE-2020-4199MEDIUM4.3IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute ma...
CVE-2020-9443MEDIUM6.1Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be expl...
CVE-2020-7002HIGH7.8Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be explo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now