2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-8644CRITICAL9.8PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
CVE-2020-6754CRITICAL9.8dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to ...
CVE-2020-6969CRITICAL9.8It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an ...
CVE-2020-6174CRITICAL9.8TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
CVE-2020-8114CRITICAL9.8GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
CVE-2020-8125CRITICAL9.8Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may re...
CVE-2020-6058CRITICAL9.1An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A ...
CVE-2020-5235CRITICAL9.8There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is ...
CVE-2020-8597CRITICAL9.8eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
CVE-2020-8592CRITICAL9.8eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password featu...
CVE-2020-8591CRITICAL9.8eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r re...
CVE-2020-8547CRITICAL9.8phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which m...
CVE-2020-8510CRITICAL9.8An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of...
CVE-2020-7471CRITICAL9.8Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a ...
CVE-2020-8508CRITICAL9.8nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of func...
CVE-2020-8515CRITICAL9.8DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow...
CVE-2020-8440CRITICAL9.8controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by ...
CVE-2020-7956CRITICAL9.8HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates use...
CVE-2020-5206CRITICAL10In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume prope...
CVE-2020-8447CRITICAL9.8In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ...
CVE-2020-8445CRITICAL9.8In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control c...
CVE-2020-8444CRITICAL9.8In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ...
CVE-2020-8443CRITICAL9.8In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an...
CVE-2020-8432CRITICAL9.8In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double free...
CVE-2020-3718CRITICAL9.8Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security by...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now