2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8356MEDIUM4.9An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, fo...
CVE-2020-35451MEDIUM4.7There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to ...
CVE-2020-27838MEDIUM6.5A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information a...
CVE-2020-27576MEDIUM5.4Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web ap...
CVE-2020-27575HIGH8.8Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functio...
CVE-2020-27574HIGH8.8Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malic...
CVE-2020-5014MEDIUM6.7IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary cod...
CVE-2020-4903MEDIUM6.5IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate ...
CVE-2020-4695HIGH7.5IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens ...
CVE-2020-27817Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA
CVE-2020-23967HIGH7.8Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges ...
CVE-2020-28466HIGH7.5This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the ser...
CVE-2020-29030HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute maliciou...
CVE-2020-29029MEDIUM6.1Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker...
CVE-2020-29028MEDIUM6.1Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javasc...
CVE-2020-29020HIGH7.2Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI ...
CVE-2020-28502HIGH8.1This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are ...
CVE-2020-35594MEDIUM6.1Zoho ManageEngine ADManager Plus before 7066 allows XSS.
CVE-2020-29032HIGH7.2Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated att...
CVE-2020-28050CRITICAL9.1Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to co...
CVE-2020-29134HIGH8.6The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all v...
CVE-2020-29658CRITICAL9.8Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to...
CVE-2020-5148HIGH8.2SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing m...
CVE-2020-36255HIGH7.5An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0. The Branca implementation allows a...
CVE-2020-25639MEDIUM4.4A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now