2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-0606HIGH8.8A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi...
CVE-2020-0605HIGH8.8A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi...
CVE-2020-0603HIGH8.8A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memor...
CVE-2020-0602HIGH7.5A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of ...
CVE-2020-0601HIGH8.1A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c...
CVE-2020-7057MEDIUM5.3Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessio...
CVE-2020-7054HIGH8.8MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer ov...
CVE-2020-7053HIGH7.8In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a us...
CVE-2020-6173MEDIUM5.3TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
CVE-2020-5509HIGH7.2PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile ima...
CVE-2020-5505CRITICAL9.8Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction...
CVE-2020-5180HIGH7.8Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be use...
CVE-2020-6307MEDIUM4.3Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) doe...
CVE-2020-6306LOW2.7Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6....
CVE-2020-6305MEDIUM6.1PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode u...
CVE-2020-6304HIGH7.5Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21,...
CVE-2020-6303MEDIUM5.4SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to C...
CVE-2020-5193MEDIUM6.1PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata...
CVE-2020-5853MEDIUM5.4In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6....
CVE-2020-5852HIGH7.5Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Microkernel (TMM). Thi...
CVE-2020-5851MEDIUM4.6On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications ...
CVE-2020-5196HIGH8.1Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create f...
CVE-2020-5194MEDIUM5.4The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip fun...
CVE-2020-6958CRITICAL9.1An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other p...
CVE-2020-6955MEDIUM6.1An issue was discovered on Cayin SMP-PRO4 devices. They allow image_preview.html?filename= reflected XSS.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now