2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25698HIGH7.5Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing cou...
CVE-2020-4701HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflo...
CVE-2020-28054HIGH7.5JamoDat TSMManager Collector version up to 6.5.0.21 is vulnerable to an Authorization Bypass because the Collector compo...
CVE-2020-8279HIGH7.4Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-mid...
CVE-2020-8277HIGH7.5A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial...
CVE-2020-13359HIGH7.6The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malici...
CVE-2020-13356HIGH8.2An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request cou...
CVE-2020-13355HIGH8.1An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS...
CVE-2020-12593HIGH7.5Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a ...
CVE-2020-26226HIGH8.1In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` c...
CVE-2020-15301HIGH7.8SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Lead...
CVE-2020-28581HIGH7.2A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 coul...
CVE-2020-28580HIGH7.2A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could a...
CVE-2020-28579HIGH8.8A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote att...
CVE-2020-28574HIGH7.5A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Securit...
CVE-2020-28572HIGH7.8A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the...
CVE-2020-27697HIGH7.8Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placin...
CVE-2020-27696HIGH7.8Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placin...
CVE-2020-27695HIGH7.8Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placin...
CVE-2020-3392HIGH7.5A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to ...
CVE-2020-3367HIGH7.8A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Secu...
CVE-2020-26076HIGH7.5A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensit...
CVE-2020-26075HIGH8.8A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker ...
CVE-2020-26072HIGH8.7A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker ...
CVE-2020-28367HIGH7.5Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now