2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-17437HIGH8.2An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP pack...
CVE-2020-13988HIGH7.5An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsin...
CVE-2020-13987HIGH7.5An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack compo...
CVE-2020-13986HIGH7.5An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling ...
CVE-2020-13985HIGH7.5An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack compone...
CVE-2020-13984HIGH7.5An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processin...
CVE-2020-5949HIGH7.5On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with a...
CVE-2020-27713HIGH7.5In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server an...
CVE-2020-7791HIGH7.5This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tag...
CVE-2020-29254HIGH8.8TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacke...
CVE-2020-27508HIGH7.5In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach th...
CVE-2020-4633HIGH8.8IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula inject...
CVE-2020-7793HIGH7.5The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexe...
CVE-2020-7792HIGH7.5This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively',...
CVE-2020-35135HIGH8.8The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.
CVE-2020-27786HIGH7.8A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permission...
CVE-2020-27828HIGH7.8There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker coul...
CVE-2020-13530HIGH7.5A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and d...
CVE-2020-13520HIGH7.8An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary US...
CVE-2020-9301HIGH8.8Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to versio...
CVE-2020-24447HIGH7Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability ...
CVE-2020-24440HIGH7Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitr...
CVE-2020-25191HIGH7.5Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user...
CVE-2020-24637HIGH7.2Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation...
CVE-2020-7560HIGH8.6A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now