2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8661HIGH7.5CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
CVE-2020-8659HIGH7.5CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many...
CVE-2020-7130HIGH7.5HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard ...
CVE-2020-9054CRITICAL9.8Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command...
CVE-2020-9550CRITICAL9.8Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attack...
CVE-2020-9477CRITICAL9.8An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in...
CVE-2020-9476HIGH7.5ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login...
CVE-2020-9372HIGH7.8The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or ...
CVE-2020-9371MEDIUM4.8Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php ...
CVE-2020-3193MEDIUM5.3A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent...
CVE-2020-3192MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent...
CVE-2020-3190MEDIUM5.8A vulnerability in the IPsec packet processor of Cisco IOS XR Software could allow an unauthenticated remote attacker to...
CVE-2020-3185MEDIUM5.4A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an authen...
CVE-2020-3182MEDIUM4.3A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow ...
CVE-2020-3181MEDIUM6.5A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in Cisco AsyncOS Softw...
CVE-2020-3176MEDIUM6.7A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on ...
CVE-2020-3164MEDIUM5.3A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco W...
CVE-2020-3157MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2020-3155HIGH7.4A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, re...
CVE-2020-3148HIGH7.1A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remot...
CVE-2020-3128HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros...
CVE-2020-3127HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros...
CVE-2020-10057HIGH8.8GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an ...
CVE-2020-9761CRITICAL9.8An issue was discovered in UNCTAD ASYCUDA World 2001 through 2020. The Java RMI Server has an Insecure Default Configura...
CVE-2020-9757CRITICAL9.8The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now