2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5525HIGH8Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS ...
CVE-2020-5524HIGH8.8Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS ...
CVE-2020-5243HIGH7.5uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regex...
CVE-2020-8960MEDIUM6.1Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
CVE-2020-8601HIGH7.8Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product in...
CVE-2020-5242HIGH8.8openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation servic...
CVE-2020-9320MEDIUM5.5Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before ...
CVE-2020-9015CRITICAL9.8Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly oth...
CVE-2020-9003MEDIUM5.4A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation...
CVE-2020-8990CRITICAL9.1Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
CVE-2020-9318HIGH7.2Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configurin...
CVE-2020-6977MEDIUM6.8A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specia...
CVE-2020-6968HIGH7.8Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges through the modification ...
CVE-2020-3765CRITICAL9.8Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could...
CVE-2020-3764HIGH7.8Adobe Media Encoder versions 14.0 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l...
CVE-2020-9283HIGH7.5golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the...
CVE-2020-9273HIGH8.8In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a u...
CVE-2020-9272HIGH7.5ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
CVE-2020-9308HIGH8.8archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupte...
CVE-2020-7942MEDIUM6.5Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the syste...
CVE-2020-6970CRITICAL9.8A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have bee...
CVE-2020-3945HIGH7.5vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosu...
CVE-2020-3944HIGH8.6vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store conf...
CVE-2020-3943CRITICAL9.8vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is ...
CVE-2020-3163MEDIUM5.9A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remot...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now