2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-7133CRITICAL9.8A unauthorized remote access vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.
CVE-2020-7131CRITICAL9This document describes a security vulnerability in Blade Maintenance Entity, Integrated Maintenance Entity and Maintena...
CVE-2020-6826CRITICAL9.8Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some ...
CVE-2020-6825CRITICAL9.8Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox...
CVE-2020-6823CRITICAL9.8A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, a...
CVE-2020-5869CRITICAL9.1In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to re...
CVE-2020-5868CRITICAL9.8In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell c...
CVE-2020-12134CRITICAL9.8Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
CVE-2020-4415CRITICAL9.8IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checki...
CVE-2020-11945CRITICAL9.8An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gai...
CVE-2020-11939CRITICAL9.8In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlle...
CVE-2020-12079CRITICAL10Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron con...
CVE-2020-10915CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4....
CVE-2020-10914CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4....
CVE-2020-7489CRITICAL9.8A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerabili...
CVE-2020-7487CRITICAL9.8A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute...
CVE-2020-7055CRITICAL9.9An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function...
CVE-2020-11796CRITICAL9.8In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
CVE-2020-11690CRITICAL9.8In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
CVE-2020-10569CRITICAL9.8SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additiona...
CVE-2020-11967CRITICAL9.8In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of ...
CVE-2020-11966CRITICAL9.8In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root p...
CVE-2020-11965CRITICAL9.8In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access vi...
CVE-2020-11963CRITICAL9.8IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because o...
CVE-2020-9279CRITICAL9.8An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now