2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35475HIGH7.5In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS ...
CVE-2020-27640HIGH8.1The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthentica...
CVE-2020-27639HIGH8.1The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an un...
CVE-2020-27154HIGH8.8The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allo...
CVE-2020-25608HIGH7.2The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input val...
CVE-2020-7838HIGH8.8A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An at...
CVE-2020-28052HIGH8.1An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility me...
CVE-2020-14232HIGH8.8A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attac...
CVE-2020-8464HIGH7.5A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests...
CVE-2020-8463HIGH7.5A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a glob...
CVE-2020-8461HIGH8.8A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an at...
CVE-2020-35491HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-35490HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-15294HIGH7Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results ...
CVE-2020-29652HIGH7.5A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go all...
CVE-2020-27199HIGH7.5The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application...
CVE-2020-25096HIGH8.8LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different ro...
CVE-2020-25095HIGH8.8LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CS...
CVE-2020-28931HIGH8.8Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthen...
CVE-2020-26274HIGH8.8In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fix...
CVE-2020-35133HIGH7.5irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32...
CVE-2020-7837HIGH8.8An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportD...
CVE-2020-5360HIGH7.5Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthent...
CVE-2020-29607HIGH7.2A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access...
CVE-2020-25622HIGH8.8An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now