2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25705HIGH7.4A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off...
CVE-2020-15349HIGH7.8BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool i...
CVE-2020-14389HIGH8.1It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources...
CVE-2020-26224HIGH7.5In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logg...
CVE-2020-28693HIGH8.8An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code t...
CVE-2020-26217HIGH8.8XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to ru...
CVE-2020-26509HIGH7.5Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.
CVE-2020-28692HIGH7.2In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for exec...
CVE-2020-23490HIGH7.5There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can...
CVE-2020-23489HIGH8.8The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion ...
CVE-2020-4700HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenti...
CVE-2020-4655HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL in...
CVE-2020-4647HIGH8.8IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote a...
CVE-2020-4476HIGH7.5IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain se...
CVE-2020-28723HIGH7.5Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.
CVE-2020-27623HIGH7.5JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
CVE-2020-27423HIGH7.5Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial o...
CVE-2020-27191HIGH7.5LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the ind...
CVE-2020-13769HIGH8.8LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device r...
CVE-2020-25209HIGH7.5In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure ...
CVE-2020-25013HIGH7.5JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
CVE-2020-8897HIGH8.1A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2...
CVE-2020-5659HIGH8.8SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary S...
CVE-2020-28649HIGH8.8The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file...
CVE-2020-28648HIGH8.8Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now