KEV 2020

146 CISA Known Exploited Vulnerabilities from 2020

Critical 60

February 2026

February 2025

January 2025

September 2024

November 2023

June 2023

April 2022

March 2022

February 2022

January 2022

December 2021

November 2021

CVE-2020-1350

SIGRed — Windows DNS Server Integer Overflow in SIG Record Parsing Enables Unauthenticated Wormable RCE; CVSS 10.0, CISA Emergency Directive ED 20-03

CVSS 10
CVE-2020-14871

Oracle Solaris — Out-of-Bounds Write in PAM Authentication Framework Enables Unauthenticated Remote Code Execution via SunSSH; CVSS 10.0, Exploited by UNC1945 Against Financial Sector

CVSS 10
CVE-2020-25213

WordPress File Manager Plugin (elFinder) — Unauthenticated File Upload via Exposed Connector Enables PHP Code Execution; 300,000+ Sites Targeted Within Hours of Disclosure

CVSS 10
CVE-2020-6287

SAP NetWeaver AS Java — RECON: Unauthenticated Access to LM Config Wizard Enables Admin User Creation; CVSS 10.0, Affects 40,000+ SAP Systems, NSA/CISA Joint Alert

CVSS 10
CVE-2020-0646

Microsoft .NET Framework — Remote Code Execution via Improper Input Validation, Patched January 2020

CVSS 9.8
CVE-2020-10148

SolarWinds Orion API — Authentication Bypass via URL Path Parameter Manipulation Enables Unauthenticated API Command Execution; Disclosed During SUNBURST Supply Chain Crisis

CVSS 9.8
CVE-2020-10181

Sumavision Enhanced Multimedia Router (EMR) — Unauthenticated Admin Account Creation via Cross-Site Request Forgery

CVSS 9.8
CVE-2020-10189

Zoho ManageEngine Desktop Central — Unauthenticated Deserialization RCE, Exploited by APT41 Within Weeks

CVSS 9.8
CVE-2020-10987

Tenda AC15 — OS Command Injection via deviceName POST Parameter in SetOnlineDevName Enables Unauthenticated Remote Code Execution; No Patch Available

CVSS 9.8
CVE-2020-11651

SaltStack Salt — Unauthenticated Access to ClearFuncs Yields Root on All Minions

CVSS 9.8
CVE-2020-12271

Sophos XG Firewall SFOS — Zero-Day SQL Injection Exploited by Chinese APT Before Patch

CVSS 9.8
CVE-2020-12812

FortiOS SSL-VPN — Case-Sensitivity Bypass Allows MFA Skip When Username Case Is Changed; Exploited by Ransomware Groups Targeting FortiGate Devices

CVSS 9.8
CVE-2020-14750

Oracle WebLogic — Unauthenticated RCE via Console Authentication Bypass; Emergency Patch for Incomplete Fix of CVE-2020-14882, Mass-Exploited Within Days of Disclosure

CVSS 9.8
CVE-2020-14882

Oracle WebLogic — Unauthenticated Console Authentication Bypass via Path Traversal Enables Admin Panel Access; Mass-Exploited Within 48 Hours, Chained with CVE-2020-14883 for Code Execution

CVSS 9.8
CVE-2020-15505

MobileIron Core / Sentry / Connector — Unauthenticated RCE via Apache/Tomcat ACL Bypass and Hessian Java Deserialization

CVSS 9.8
CVE-2020-16846

SaltStack Salt — Unauthenticated RCE via Salt API SSH Client

CVSS 9.8
CVE-2020-17496

vBulletin — Unauthenticated RCE via Crafted subWidgets Data in Widget Render Endpoint; Bypass of Incomplete CVE-2019-16759 Patch, Exploited Within Hours of Disclosure

CVSS 9.8
CVE-2020-17530

Apache Struts S2-061 — Forced OGNL Evaluation in Tag Attributes Enables Unauthenticated Remote Code Execution; Bypass of S2-059 Fix in Struts 2.5.26

CVSS 9.8
CVE-2020-25506

D-Link DNS-320 NAS — Unauthenticated OS Command Injection in system_mgr.cgi Enables Remote Code Execution; No Patch Available for End-of-Life Device

CVSS 9.8
CVE-2020-2555

Oracle Coherence — Unauthenticated Deserialization RCE via T3, Reaching Products That Bundle It as a Hidden Dependency

CVSS 9.8
CVE-2020-26919

NETGEAR JGS516PE ProSAFE Plus — Unauthenticated Access to Switch Management Functions via Missing Access Control; Enables Full Switch Takeover and Network Manipulation

CVSS 9.8
CVE-2020-29557

D-Link DIR-825 R1 Router — Buffer Overflow in Web Interface Enables Unauthenticated Remote Code Execution; No Patch Available for Revision 1 Hardware

CVSS 9.8
CVE-2020-29583

Zyxel Firewalls and AP Controllers — Hardcoded 'zyfwp' Admin Account with Fixed Password Enables Unauthenticated Network Takeover; Discovered by Eye Control

CVSS 9.8
CVE-2020-3161

Cisco IP Phones — Unauthenticated RCE or DoS via HTTP Request Handling Flaw

CVSS 9.8
CVE-2020-3952

VMware vCenter Server — vmdir LDAP Access Control Bypass Exposes All Credentials

CVSS 9.8
CVE-2020-3992

VMware ESXi OpenSLP — Use-After-Free in Service Location Protocol Daemon Enables Unauthenticated RCE from Management Network; Exploited by ESXiArgs and BlackBasta Ransomware

CVSS 9.8
CVE-2020-4427

IBM Data Risk Manager — Authentication Bypass Giving Full Admin Access

CVSS 9.8
CVE-2020-5847

Unraid — PHP extract() Abuse Enabling Root RCE, Chained with CVE-2020-5849 Auth Bypass

CVSS 9.8
CVE-2020-5902

F5 BIG-IP — Unauthenticated RCE via TMUI Path Traversal (CVE of the Year 2020)

CVSS 9.8
CVE-2020-6207

SAP Solution Manager — Unauthenticated EEM Servlet Access Leads to Landscape-Wide SMD Agent Compromise

CVSS 9.8
CVE-2020-7961

Liferay Portal — Unauthenticated RCE via JSON Web Services Java Deserialization

CVSS 9.8
CVE-2020-8515

DrayTek Vigor3900/2960/300B — Unauthenticated OS Command Injection in the Web Management Interface

CVSS 9.8
CVE-2020-8599

Trend Micro Apex One and OfficeScan — Critical Unauthenticated Auth Bypass via Vulnerable EXE Grants Admin Access Without Credentials; Enables CVE-2020-8467 RCE Chain

CVSS 9.8
CVE-2020-8644

PlaySMS — Server-Side Template Injection via the SMS Banner Feature Leads to RCE

CVSS 9.8
CVE-2020-8657

EyesOfNetwork — Shared Default API Key Lets Any Attacker Compute the Admin Access Token

CVSS 9.8
CVE-2020-15999

Chrome FreeType — Heap Buffer Overflow in PNG-in-Font Processing Enables Renderer Code Execution; Zero-Day Chained with CVE-2020-17087 (Windows) and CVE-2020-16010 (Android)

CVSS 9.6
CVE-2020-16010

Chrome for Android — Heap Buffer Overflow in Chrome UI Enables Compromised Renderer to Escape Android Sandbox; Zero-Day Chained with CVE-2020-15999 for Full Device Compromise

CVSS 9.6
CVE-2020-16017

Chrome Site Isolation — Use-After-Free in Site Isolation Enables Compromised Renderer to Escape Sandbox; Zero-Day Used with V8 Bug CVE-2020-16013

CVSS 9.6
CVE-2020-4006

VMware Workspace ONE Access — Command Injection in Admin Configurator Enables OS Command Execution; NSA-Attributed Russian SVR Exploitation for SAML Token Forgery

CVSS 9.1
CVE-2020-4428

IBM Data Risk Manager — OS Command Injection RCE, Chainable from Auth Bypass

CVSS 9.1
CVE-2020-1040

Hyper-V RemoteFX vGPU — Authenticated Guest VM User Achieves Host Hypervisor Code Execution via Crafted Input; VM Escape Patched July 2020, RemoteFX vGPU Subsequently Removed

CVSS 9

High 70

April 2026

September 2025

August 2025

September 2024

May 2024

February 2024

March 2023

October 2022

August 2022

June 2022

May 2022

March 2022

January 2022

December 2021

November 2021

CVE-2020-0688

Exchange Control Panel — Static Machine Key Enables Post-Auth Deserialization RCE, Mass-Scanned Within Days

CVSS 8.8
CVE-2020-10199

Sonatype Nexus Repository Manager — Authenticated RCE via Expression Language Injection, Exploited by Cryptominers

CVSS 8.8
CVE-2020-1020

Windows Adobe Type Manager Library — The Second ADV200006 0-Day, Fixed Alongside CVE-2020-0938

CVSS 8.8
CVE-2020-10221

rConfig — Unauthenticated OS Command Injection via ajaxAddTemplate.php, Rapidly Weaponized After Disclosure

CVSS 8.8
CVE-2020-16009

Chromium V8 — Type Confusion 0-Day From the Same Late-2020 Actively-Exploited Cluster as CVE-2020-16013

CVSS 8.8
CVE-2020-16013

Chromium V8 — Actively Exploited Heap-Corruption 0-Day, Part of an October–November 2020 Chrome/Windows Exploit Chain

CVSS 8.8
CVE-2020-3118

Cisco IOS XR — CDP Format String Bug Allows Adjacent Attacker to Gain Admin-Level Code Execution

CVSS 8.8
CVE-2020-5735

Amcrest Cameras/NVR — Stack Buffer Overflow via the Dahua-Derived Port 37777 Protocol

CVSS 8.8
CVE-2020-6418

Chromium V8 — Actively Exploited Type Confusion, Among the First Confirmed Chrome 0-Days of 2020

CVSS 8.8
CVE-2020-8467

Trend Micro Apex One and OfficeScan — Migration Tool Component RCE; Chained with Auth Bypass CVE-2020-8599 for Unauthenticated RCE in Active Exploitation

CVSS 8.8
CVE-2020-8468

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security — Agent Content Validation Escape Allows Low-Privilege Attacker to Manipulate Agent Components

CVSS 8.8
CVE-2020-9818

Apple Mail (iOS/iPadOS/watchOS) — Out-of-Bounds Write via a Maliciously Crafted Mail Message

CVSS 8.8
CVE-2020-3566

Cisco IOS XR — DVMRP Memory Exhaustion DoS (Companion Advisory to CVE-2020-3569)

CVSS 8.6
CVE-2020-3569

Cisco IOS XR — DVMRP Memory Exhaustion DoS, Exploited as a 0-Day Before Cisco Had a Fix Ready

CVSS 8.6
CVE-2020-17144

Microsoft Exchange Server — Post-Auth RCE via Malformed Cmdlet Arguments, Patched December 2020

CVSS 8.4
CVE-2020-0601

'CurveBall' — Windows CryptoAPI ECC Certificate Validation Bypass Enabling Code-Signing Spoofing and TLS MITM

CVSS 8.1
CVE-2020-6819

Firefox/Thunderbird — nsDocShell Race-Condition UAF, Patched via Emergency Release After Active Exploitation Reports

CVSS 8.1
CVE-2020-6820

Firefox/Thunderbird — ReadableStream Race-Condition UAF, Fixed in the Same Emergency Release as CVE-2020-6819

CVSS 8.1
CVE-2020-0041

Android Kernel (binder.c) — Root Primitive in the "AbstractEmu" Rooting Malware Framework Found on Google Play

CVSS 7.8
CVE-2020-0069

MediaTek Chipsets — The "MediaTek-su" Root Exploit, Later Weaponized in the AbstractEmu Malware Chain

CVSS 7.8
CVE-2020-0683

Windows Installer — Symbolic Link Handling Flaw Enables Local Privilege Escalation to SYSTEM

CVSS 7.8
CVE-2020-0938

Windows Adobe Type Manager Library — The ADV200006 0-Day, Publicly Disclosed Before a Patch Existed

CVSS 7.8
CVE-2020-0986

Windows GDI Print Spooler (splwow64) — The Kernel Half of Kaspersky's "Operation PowerFall" Exploit Chain

CVSS 7.8
CVE-2020-1054

Windows Win32k — Kernel-Mode Driver EoP, Part of a Recurring 2020 Pattern of Actively-Exploited Win32k 0-Days

CVSS 7.8
CVE-2020-1147

Microsoft .NET Framework, SharePoint, Visual Studio — Shared XML Processing RCE Across Three Product Lines

CVSS 7.8
CVE-2020-1380

Internet Explorer — "Operation PowerFall": A Kaspersky-Discovered 0-Day Chain Targeting South Korean Users

CVSS 7.8
CVE-2020-1464

Windows — "GlueBall": A File-Signature Validation Bypass Exploited in the Wild for Years Before Patching

CVSS 7.8
CVE-2020-17087

Windows Kernel (cng.sys) — Project Zero–Disclosed 0-Day Chained With a Chrome RCE for Sandbox Escape

CVSS 7.8
CVE-2020-24557

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security — Agent Folder Manipulation Disables AV Protection and Escalates to SYSTEM via Windows Privilege Abuse

CVSS 7.8
CVE-2020-27930

Apple iOS/iPadOS/macOS/watchOS — FontParser RCE, Part of a Project Zero–Reported November 2020 0-Day Trio

CVSS 7.8
CVE-2020-27932

Apple iOS/iPadOS/macOS/watchOS — Kernel Type Confusion Privilege Escalation, Part of the Same November 2020 0-Day Trio

CVSS 7.8
CVE-2020-3950

VMware Fusion/VMRC/Horizon Client for Mac — Root Privilege Escalation via Improper setuid Binary Handling

CVSS 7.8
CVE-2020-8655

EyesOfNetwork — Crafted Nmap NSE Script Enables Local Privilege Escalation to Root

CVSS 7.8
CVE-2020-9859

Apple iOS/iPadOS/macOS/watchOS/tvOS — Double-Free Enabling Kernel-Privileged Code Execution

CVSS 7.8
CVE-2020-0674

Internet Explorer (jscript.dll) — ADV200001: A January 2020 0-Day Disclosed Before Its Patch Existed

CVSS 7.5
CVE-2020-0968

Internet Explorer — Scripting Engine 0-Day Reported by Google TAG, Patched April 2020

CVSS 7.5
CVE-2020-11738

WordPress Duplicator Plugin — Leftover installer.php Exposes Full-Site Backup Archives Including wp-config.php

CVSS 7.5
CVE-2020-3452

Cisco ASA/FTD — Unauthenticated WebVPN Path Traversal, Mass-Scanned Within Days of Disclosure

CVSS 7.5
CVE-2020-5849

Unraid — Authentication Bypass Chainable With CVE-2020-5847 for Remote Code Execution

CVSS 7.5
CVE-2020-14883

Oracle WebLogic Server — Console RCE Chained With CVE-2020-14882's Auth Bypass for Unauthenticated Takeover

CVSS 7.2
CVE-2020-8243

Pulse Connect Secure — Authenticated Admin RCE via Custom Template Upload

CVSS 7.2
CVE-2020-8260

Pulse Connect Secure — Authenticated Admin RCE via Uncontrolled Archive Extraction

CVSS 7.2

Medium 16

January 2025

June 2024

June 2023

October 2022

September 2022

March 2022

November 2021