2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25660HIGH8.8A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not ve...
CVE-2020-26228HIGH7.5TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user sessio...
CVE-2020-24227HIGH7.5Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with a...
CVE-2020-15246HIGH7.5October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version...
CVE-2020-12351HIGH8.8Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a...
CVE-2020-7777HIGH7.2This affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript...
CVE-2020-28421HIGH7.8CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that ...
CVE-2020-7925HIGH7.5Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthent...
CVE-2020-27985HIGH7.8Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain ro...
CVE-2020-28975HIGH7.5svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cau...
CVE-2020-14258HIGH7.5HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A re...
CVE-2020-14234HIGH7.5HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potent...
CVE-2020-14230HIGH7.5HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A r...
CVE-2020-25185HIGH8.8The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to rem...
CVE-2020-4005HIGH7.8VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a...
CVE-2020-4004HIGH8.2VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstati...
CVE-2020-28845HIGH7.8A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious p...
CVE-2020-20740HIGH7.8PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
CVE-2020-26236HIGH7.5In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's acc...
CVE-2020-19667HIGH7.8Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.
CVE-2020-13671HIGH8.8Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as...
CVE-2020-4937HIGH7.5IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms ...
CVE-2020-4739HIGH7.8IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9....
CVE-2020-5668HIGH7.5Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and ea...
CVE-2020-7572HIGH8.8A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation W...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now