2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-1602HIGH8.8When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos O...
CVE-2020-1601HIGH7.5Certain types of malformed Path Computation Element Protocol (PCEP) packets when received and processed by a Juniper Net...
CVE-2020-1600MEDIUM6.5In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability i...
CVE-2020-7058HIGH8.8data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input M...
CVE-2020-5502MEDIUM6.5phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.
CVE-2020-5501MEDIUM4.3phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
CVE-2020-0656MEDIUM5.4A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci...
CVE-2020-0654CRITICAL9.1A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to byp...
CVE-2020-0653HIGH7.8A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2020-0652HIGH7.8A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle obj...
CVE-2020-0651HIGH7.8A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2020-0650HIGH7.8A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2020-0647MEDIUM5.4A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, ak...
CVE-2020-0646CRITICAL9.8A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N...
CVE-2020-0644HIGH7.8An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka '...
CVE-2020-0643MEDIUM5.5An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles...
CVE-2020-0642HIGH7.8An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2020-0641HIGH7.8An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations...
CVE-2020-0640HIGH7.5A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet...
CVE-2020-0639MEDIUM5.5An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to prop...
CVE-2020-0638HIGH7.8An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this ...
CVE-2020-0637MEDIUM6.5An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information,...
CVE-2020-0636HIGH7.8An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windo...
CVE-2020-0635HIGH7.8An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbol...
CVE-2020-0634HIGH7.8An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now