2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3160MEDIUM5.3A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could ...
CVE-2020-3159MEDIUM6.1A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t...
CVE-2020-3158CRITICAL9.1A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthentic...
CVE-2020-3156MEDIUM6.1A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated remote attacke...
CVE-2020-3154MEDIUM4.9A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute...
CVE-2020-3153MEDIUM6.5A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authent...
CVE-2020-3138MEDIUM6.7A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenti...
CVE-2020-3132MEDIUM5.9A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)...
CVE-2020-3114HIGH8.8A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2020-3113MEDIUM5.4A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent...
CVE-2020-3112HIGH8.8A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remot...
CVE-2020-6062HIGH7.5An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A speci...
CVE-2020-6061CRITICAL9.8An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A...
CVE-2020-8959HIGH7.8Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
CVE-2020-8824MEDIUM5.4Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed De...
CVE-2020-8441CRITICAL9.8JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function...
CVE-2020-4230MEDIUM6.7IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privil...
CVE-2020-4204HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buf...
CVE-2020-4200MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated atta...
CVE-2020-4161MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a ...
CVE-2020-4135HIGH7.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe...
CVE-2020-8633MEDIUM5.3An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calend...
CVE-2020-7796CRITICAL9.8Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enab...
CVE-2020-9271MEDIUM6.5ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
CVE-2020-9270HIGH8.8ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now