2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36251MEDIUM4.3ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove...
CVE-2020-36250MEDIUM4.6In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system ...
CVE-2020-36249HIGH7.5The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.
CVE-2020-10254MEDIUM5.9An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by ...
CVE-2020-10252HIGH8.3An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote pa...
CVE-2020-36247HIGH8.8Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.
CVE-2020-24908HIGH7.8Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDA...
CVE-2020-36246HIGH7.8Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.
CVE-2020-19513HIGH7.8Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a craf...
CVE-2020-36233HIGH7.8The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, ...
CVE-2020-35776MEDIUM6.5A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remo...
CVE-2020-35592MEDIUM5.4Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitra...
CVE-2020-35591MEDIUM5.4Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the us...
CVE-2020-28499CRITICAL9.8All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .
CVE-2020-28491HIGH7.5This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-...
CVE-2020-28463MEDIUM6.5All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce ...
CVE-2020-4933MEDIUM5.4IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allo...
CVE-2020-28496HIGH7.5This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require...
CVE-2020-28490CRITICAL9.8The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For exam...
CVE-2020-35577MEDIUM6.5In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to ...
CVE-2020-29664HIGH7.8A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code...
CVE-2020-9306HIGH8.8Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi Connec...
CVE-2020-12878HIGH7.8Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlin...
CVE-2020-8625HIGH8.1BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a co...
CVE-2020-36245HIGH8.8GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now