2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15707MEDIUM6.4Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRU...
CVE-2020-15706MEDIUM6.4GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be ...
CVE-2020-15705MEDIUM6.4GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This on...
CVE-2020-11934MEDIUM5.9It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the syste...
CVE-2020-11933MEDIUM6.8cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, ...
CVE-2020-8553MEDIUM5.9The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and t...
CVE-2020-16095MEDIUM6.1The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.
CVE-2020-4645MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2020-4644MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the vi...
CVE-2020-4573MEDIUM5.3IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated...
CVE-2020-4572MEDIUM5.3IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a deta...
CVE-2020-4569MEDIUM6.5IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an ...
CVE-2020-2078MEDIUM6.5Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1...
CVE-2020-9692MEDIUM6.5Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Success...
CVE-2020-9690MEDIUM4.2Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Suc...
CVE-2020-9689MEDIUM6.5Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploita...
CVE-2020-14492MEDIUM6.1OpenClinic GA 5.09.02 and 5.89.05b does not properly neutralize user-controllable input, which may allow the execution o...
CVE-2020-5614MEDIUM5.3Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unsp...
CVE-2020-5613MEDIUM6.1Cross-site scripting vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to execute an arbitrary script ...
CVE-2020-5612MEDIUM6.1Cross-site scripting vulnerability in KonaWiki 2.2.0 and earlier allows remote attackers to execute an arbitrary script ...
CVE-2020-13971MEDIUM5.4In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG image...
CVE-2020-10985MEDIUM4.8Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.
CVE-2020-10983MEDIUM4.9Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.
CVE-2020-10982MEDIUM4.9Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.
CVE-2020-15417MEDIUM6.3This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now