2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13497MEDIUM5.5An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra...
CVE-2020-13496MEDIUM6.5An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra...
CVE-2020-13494MEDIUM5.5A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files....
CVE-2020-29240MEDIUM4.8Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of t...
CVE-2020-29239MEDIUM6.1Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result i...
CVE-2020-25266MEDIUM5.5AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it w...
CVE-2020-25265MEDIUM6.5AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by provid...
CVE-2020-13956MEDIUM5.3Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request U...
CVE-2020-14369MEDIUM6.3This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to ...
CVE-2020-29456MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrar...
CVE-2020-29454MEDIUM4.3Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Ap...
CVE-2020-4102MEDIUM6.7HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successfu...
CVE-2020-27816MEDIUM6.1The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it i...
CVE-2020-25704MEDIUM5.5A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET...
CVE-2020-25656MEDIUM4.1A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKB...
CVE-2020-14383MEDIUM6.5A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC s...
CVE-2020-26250MEDIUM6.3OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the ...
CVE-2020-28583MEDIUM5.3An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo...
CVE-2020-28582MEDIUM5.3An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo...
CVE-2020-28577MEDIUM5.3An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo...
CVE-2020-28576MEDIUM5.3An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo...
CVE-2020-28575MEDIUM6.7A heap-based buffer overflow privilege escalation vulnerability in Trend Micro ServerProtect for Linux 3.0 may allow an ...
CVE-2020-28573MEDIUM5.3An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo...
CVE-2020-29315MEDIUM5.4ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script ...
CVE-2020-7546MEDIUM5.4A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStru...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now