2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8645CRITICAL9.8An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job a...
CVE-2020-6760CRITICAL9.8Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry...
CVE-2020-8657CRITICAL9.8An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include...
CVE-2020-5319HIGH7.5Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vul...
CVE-2020-5318HIGH7.5Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An a...
CVE-2020-5317MEDIUM4.8Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit...
CVE-2020-8772CRITICAL9.8The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in in...
CVE-2020-8771CRITICAL9.8The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFI...
CVE-2020-8636CRITICAL9.8An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .
CVE-2020-8608MEDIUM5.6In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in lat...
CVE-2020-7954HIGH7.8An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform priv...
CVE-2020-7953HIGH7.5An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /e...
CVE-2020-7920HIGH7.5pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
CVE-2020-6856MEDIUM6.5An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allow...
CVE-2020-6855MEDIUM6.5A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers...
CVE-2020-6767MEDIUM6.5A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated r...
CVE-2020-5720MEDIUM5.9MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wher...
CVE-2020-5856HIGH7.5On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' dr...
CVE-2020-5855MEDIUM4.3When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorize...
CVE-2020-5854MEDIUM5.9On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm ...
CVE-2020-5528MEDIUM6.1Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable T...
CVE-2020-8658HIGH8.8The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_...
CVE-2020-8649MEDIUM5.9There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in driver...
CVE-2020-8648HIGH7.1There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in dr...
CVE-2020-8647MEDIUM6.1There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now