2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15128MEDIUM6.3In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged...
CVE-2020-9249MEDIUM6.5HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service vulnerability. A mod...
CVE-2020-9248MEDIUM6.7Huawei FusionComput 8.0.0 have an improper authorization vulnerability. A module does not verify some input correctly an...
CVE-2020-14337MEDIUM5.8A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw a...
CVE-2020-3462MEDIUM6.3A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent...
CVE-2020-3461MEDIUM5.3A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2020-3460MEDIUM6.1A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2020-7205MEDIUM6.7A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and H...
CVE-2020-15129MEDIUM4.7In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik...
CVE-2020-16157MEDIUM5.4A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
CVE-2020-15511MEDIUM5.3HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when ...
CVE-2020-8222MEDIUM6.8A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the admi...
CVE-2020-8221MEDIUM4.9A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbi...
CVE-2020-8220MEDIUM6.5A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform...
CVE-2020-8217MEDIUM5.4A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used f...
CVE-2020-8216MEDIUM4.3An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to ...
CVE-2020-8213MEDIUM5.3An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attacke...
CVE-2020-8204MEDIUM6.1A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
CVE-2020-8202MEDIUM5.3Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when ...
CVE-2020-8192MEDIUM6.5A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger reso...
CVE-2020-4186MEDIUM5.3IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in furt...
CVE-2020-14309MEDIUM6.7There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link wi...
CVE-2020-16135MEDIUM5.9libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
CVE-2020-14308MEDIUM6.4In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested...
CVE-2020-16117MEDIUM5.9In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer derefere...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now