2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25533HIGH7An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged ac...
CVE-2020-24641HIGH7.5In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated end...
CVE-2020-24638HIGH7.2Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. Thes...
CVE-2020-35749HIGH7.7Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2...
CVE-2020-35733HIGH7.5An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certif...
CVE-2020-27220HIGH8.8The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to r...
CVE-2020-6572HIGH8.8Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a...
CVE-2020-29494HIGH8.7Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could po...
CVE-2020-6776HIGH8.8A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAE...
CVE-2020-29018HIGH8.8A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the co...
CVE-2020-29017HIGH8.8An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to ...
CVE-2020-26732HIGH7.5SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie ...
CVE-2020-16119HIGH7.8Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an a...
CVE-2020-14102HIGH7.2There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root priv...
CVE-2020-14101HIGH7.5The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi rout...
CVE-2020-14098HIGH7.5The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts....
CVE-2020-14097HIGH7.5Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6...
CVE-2020-35578HIGH7.2An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature...
CVE-2020-4596HIGH7.5IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to ...
CVE-2020-4595HIGH7.5IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to ...
CVE-2020-4594HIGH7.5IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to ...
CVE-2020-26262HIGH7.2Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow...
CVE-2020-5686HIGH7.5Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from...
CVE-2020-35686HIGH7.8The SECOMN service in Sound Research DCHU model software component modules (APO) through 2.0.9.17, delivered on HP Windo...
CVE-2020-28374HIGH8.1In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCS...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now