2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-26511HIGH7.5The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This lead...
CVE-2020-9491HIGH7.5In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connectio...
CVE-2020-9487HIGH7.5In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did no...
CVE-2020-9486HIGH7.5In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive proper...
CVE-2020-5786HIGH8.8Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive applica...
CVE-2020-11979HIGH7.5As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the...
CVE-2020-15678HIGH8.8When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential u...
CVE-2020-15675HIGH8.8When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially ex...
CVE-2020-15674HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corru...
CVE-2020-15673HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evi...
CVE-2020-15670HIGH8.8Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of ...
CVE-2020-15669HIGH8.8When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. T...
CVE-2020-15667HIGH8.8When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap...
CVE-2020-15663HIGH8.8If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the...
CVE-2020-25018HIGH7.5Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.
CVE-2020-25017HIGH8.3Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy...
CVE-2020-24620HIGH7.8Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager ...
CVE-2020-4576HIGH7.5IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive in...
CVE-2020-8109HIGH7.5A vulnerability has been discovered in the ace.xmd parser that results from a lack of proper validation of user-supplied...
CVE-2020-6654HIGH7.8A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attac...
CVE-2020-16234HIGH7.8In PLC WinProladder Version 3.28 and prior, a stack-based buffer overflow vulnerability can be exploited when a valid us...
CVE-2020-13952HIGH8.1In the course of work on the open source project it was discovered that authenticated users running queries against Hive...
CVE-2020-12715HIGH8.8RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.
CVE-2020-14374HIGH8.8A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data funct...
CVE-2020-15849HIGH7.2Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTem...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now