2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-7512CRITICAL9.8A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (...
CVE-2020-7508CRITICAL9.8A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware versi...
CVE-2020-7500CRITICAL9.8A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U....
CVE-2020-7498CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions)....
CVE-2020-7497CRITICAL9.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStru...
CVE-2020-9296CRITICAL9.8Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violatio...
CVE-2020-0235CRITICAL9.8In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size...
CVE-2020-0232CRITICAL9.8Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work wi...
CVE-2020-0223CRITICAL9.8This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Androi...
CVE-2020-5754CRITICAL9.1Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability ov...
CVE-2020-12019CRITICAL9.8WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to re...
CVE-2020-12001CRITICAL9.8FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio...
CVE-2020-11969CRITICAL9.8If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter...
CVE-2020-14034CRITICAL9.8An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c ha...
CVE-2020-14033CRITICAL9.8An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plu...
CVE-2020-14054CRITICAL9.8SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows r...
CVE-2020-14011CRITICAL9.8Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin accoun...
CVE-2020-4469CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. B...
CVE-2020-4216CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key...
CVE-2020-0595CRITICAL9.8Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.6...
CVE-2020-0594CRITICAL9.8Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12...
CVE-2020-14080CRITICAL9.8TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows...
CVE-2020-14067CRITICAL9.8The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files with...
CVE-2020-13656CRITICAL9.8In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an...
CVE-2020-9633CRITICAL9.8Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now