2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-8899CRITICAL9.8There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q...
CVE-2020-3318CRITICAL9.8Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software cou...
CVE-2020-3187CRITICAL9.1A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th...
CVE-2020-3125CRITICAL9.8A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow a...
CVE-2020-7806CRITICAL9.8Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supporte...
CVE-2020-11035CRITICAL9.3In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The im...
CVE-2020-10634CRITICAL9.1SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file s...
CVE-2020-12641CRITICAL9.8rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in...
CVE-2020-12640CRITICAL9.8Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plu...
CVE-2020-8790CRITICAL9.8The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combi...
CVE-2020-12110CRITICAL9.8Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304,...
CVE-2020-1961CRITICAL9.8Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1...
CVE-2020-1959CRITICAL9.8A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary ...
CVE-2020-1631CRITICAL9.8A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication...
CVE-2020-12627CRITICAL9.8Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.
CVE-2020-7645CRITICAL9.8All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in ...
CVE-2020-10683CRITICAL9.8dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE ...
CVE-2020-5887CRITICAL9.1On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism fo...
CVE-2020-5886CRITICAL9.1On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection ...
CVE-2020-5885CRITICAL9.1On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection...
CVE-2020-5884CRITICAL9.1On versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.4, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the default deploym...
CVE-2020-7136CRITICAL9.8A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access...
CVE-2020-11015CRITICAL9.1A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC add...
CVE-2020-11651CRITICAL9.8An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla...
CVE-2020-11942CRITICAL9.8An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now