2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9449HIGH8.8An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (clien...
CVE-2020-9466MEDIUM6.1The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.
CVE-2020-9465CRITICAL9.8An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL...
CVE-2020-8132CRITICAL9.8Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF fi...
CVE-2020-8127MEDIUM6.1Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attacke...
CVE-2020-1881HIGH7.5NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have have ...
CVE-2020-1877MEDIUM4.4NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid poi...
CVE-2020-1876HIGH7.5NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-boun...
CVE-2020-1875MEDIUM5.5NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid...
CVE-2020-1874MEDIUM5.5NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid ...
CVE-2020-1873HIGH7.5NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an ou...
CVE-2020-1861MEDIUM4.4CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PW...
CVE-2020-1860HIGH7.5NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an ac...
CVE-2020-1844HIGH7.8PCManager with versions earlier than 10.0.5.51 have a privilege escalation vulnerability in Huawei PCManager products. A...
CVE-2020-1792MEDIUM5.5Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0...
CVE-2020-9463HIGH8.8Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server...
CVE-2020-5247HIGH7.5In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response head...
CVE-2020-9447MEDIUM6.1There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can up...
CVE-2020-9442HIGH7.8OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10,...
CVE-2020-9399MEDIUM5.5The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 def...
CVE-2020-9434CRITICAL9.1openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean...
CVE-2020-9433CRITICAL9.1openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean ...
CVE-2020-9432CRITICAL9.1openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean f...
CVE-2020-9431HIGH7.5In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addr...
CVE-2020-9430HIGH7.5In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addres...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now