2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36387HIGH7.8An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_fu...
CVE-2020-36386HIGH7.1An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci...
CVE-2020-1742HIGH7An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacke...
CVE-2020-1690MEDIUM6.5An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root...
CVE-2020-18268MEDIUM6.1Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect"...
CVE-2020-18265HIGH8.8Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary cod...
CVE-2020-18264HIGH8.8Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary cod...
CVE-2020-1719MEDIUM5.4A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Se...
CVE-2020-5008MEDIUM5.3IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET r...
CVE-2020-36385HIGH7.8An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the...
CVE-2020-36384MEDIUM6.1PageLayer before 1.3.5 allows reflected XSS via color settings.
CVE-2020-36383MEDIUM6.1PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
CVE-2020-26885MEDIUM6.1An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an ...
CVE-2020-29324HIGH7.5The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation o...
CVE-2020-29323HIGH7.5The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decom...
CVE-2020-29322HIGH7.5The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmw...
CVE-2020-29321HIGH7.5The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmw...
CVE-2020-36142MEDIUM6.5BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
CVE-2020-36141HIGH8.8BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpe...
CVE-2020-36140MEDIUM6.5BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of '...
CVE-2020-36139MEDIUM5.4BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'file...
CVE-2020-27302HIGH8A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "me...
CVE-2020-27301HIGH8A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AE...
CVE-2020-7469HIGH7.5In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 1...
CVE-2020-36382HIGH7.5OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase v...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now