2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-13092CRITICAL9.8scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to ...
CVE-2020-13091CRITICAL9.8pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() fun...
CVE-2020-12889CRITICAL9.8MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.
CVE-2020-12651CRITICAL9.8SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow b...
CVE-2020-12834CRITICAL9.8eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSO...
CVE-2020-10620CRITICAL9.8Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an at...
CVE-2020-10612CRITICAL9.1Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. Ho...
CVE-2020-0221CRITICAL9.8Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation...
CVE-2020-0103CRITICAL9.8In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This coul...
CVE-2020-12874CRITICAL9.8Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication ...
CVE-2020-11973CRITICAL9.8Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1...
CVE-2020-11972CRITICAL9.8Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to ...
CVE-2020-11066CRITICAL10In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4....
CVE-2020-2018CRITICAL9An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access ...
CVE-2020-2001CRITICAL9.8An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that ...
CVE-2020-12832CRITICAL9.8WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files be...
CVE-2020-9502CRITICAL9.8Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user...
CVE-2020-7454CRITICAL9.8In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3...
CVE-2020-12763CRITICAL9.8TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow i...
CVE-2020-10654CRITICAL9.8Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be...
CVE-2020-6242CRITICAL9.8SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an att...
CVE-2020-12823CRITICAL9.8OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other im...
CVE-2020-1939CRITICAL9.8The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional co...
CVE-2020-8159CRITICAL9.8There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a w...
CVE-2020-10022CRITICAL9.8A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now