2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8003MEDIUM5.5A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of ser...
CVE-2020-8002MEDIUM5.5A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of serv...
CVE-2020-8001CRITICAL9.8The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.
CVE-2020-8000CRITICAL9.8Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.
CVE-2020-7999CRITICAL9.8The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.
CVE-2020-7996MEDIUM6.1htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
CVE-2020-7995CRITICAL9.8The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attem...
CVE-2020-7994MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web sc...
CVE-2020-7991HIGH8.8Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
CVE-2020-7990MEDIUM6.1Adive Framework 2.0.8 has admin/user/add userName XSS.
CVE-2020-7989MEDIUM6.1Adive Framework 2.0.8 has admin/user/add userUsername XSS.
CVE-2020-7984HIGH7.5SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain ad...
CVE-2020-3142HIGH7.5A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated...
CVE-2020-3139MEDIUM5.3A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Inf...
CVE-2020-3136MEDIUM6.1A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attac...
CVE-2020-3134MEDIUM6.5A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could...
CVE-2020-3131MEDIUM6.5A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the c...
CVE-2020-3129MEDIUM4.8A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, r...
CVE-2020-3121MEDIUM6.1A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an ...
CVE-2020-3115HIGH8.8A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to...
CVE-2020-7981CRITICAL9.8sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with ...
CVE-2020-7980CRITICAL9.8Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th...
CVE-2020-7596HIGH8.8Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
CVE-2020-5226MEDIUM5.4Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be su...
CVE-2020-5225MEDIUM5.4Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and se...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now