2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-10547CRITICAL9.8rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by defa...
CVE-2020-10546CRITICAL9.8rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, n...
CVE-2020-11094CRITICAL9.8The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all informat...
CVE-2020-6493CRITICAL9.6Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised...
CVE-2020-3258CRITICAL9.8Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ...
CVE-2020-3227CRITICAL9.8A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Softw...
CVE-2020-3198CRITICAL9.8Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ...
CVE-2020-4177CRITICAL9.8IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i...
CVE-2020-13756CRITICAL9.8Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the...
CVE-2020-10516CRITICAL9.8An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization...
CVE-2020-7115CRITICAL9.8The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon succ...
CVE-2020-1963CRITICAL9.1Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used ...
CVE-2020-12017CRITICAL9.8GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerab...
CVE-2020-3641CRITICAL9.8Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdra...
CVE-2020-3633CRITICAL9.8Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allo...
CVE-2020-3615CRITICAL9.8Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disas...
CVE-2020-8967CRITICAL9.8There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php file...
CVE-2020-11844CRITICAL9.8Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybri...
CVE-2020-12493CRITICAL10An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the...
CVE-2020-13693CRITICAL9.8An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi...
CVE-2020-11079CRITICAL9.8node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote...
CVE-2020-7812CRITICAL9.8Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allo...
CVE-2020-8606CRITICAL9.8A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authent...
CVE-2020-11075CRITICAL9.9In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to t...
CVE-2020-6831CRITICAL9.8A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruptio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now