2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36251 | MEDIUM | 4.3 | 0.6% | Feb 19, 2021 | ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove... |
| CVE-2020-36250 | MEDIUM | 4.6 | 0.3% | Feb 19, 2021 | In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system ... |
| CVE-2020-36249 | HIGH | 7.5 | 0.8% | Feb 19, 2021 | The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares. |
| CVE-2020-10254 | MEDIUM | 5.9 | 1.6% | Feb 19, 2021 | An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by ... |
| CVE-2020-10252 | HIGH | 8.3 | 1.2% | Feb 19, 2021 | An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote pa... |
| CVE-2020-36247 | HIGH | 8.8 | 0.4% | Feb 19, 2021 | Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF. |
| CVE-2020-24908 | HIGH | 7.8 | 0.3% | Feb 19, 2021 | Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDA... |
| CVE-2020-36246 | HIGH | 7.8 | 0.5% | Feb 19, 2021 | Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link. |
| CVE-2020-19513 | HIGH | 7.8 | 0.5% | Feb 19, 2021 | Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a craf... |
| CVE-2020-36233 | HIGH | 7.8 | 0.3% | Feb 18, 2021 | The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, ... |
| CVE-2020-35776 | MEDIUM | 6.5 | 3.9% | Feb 18, 2021 | A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remo... |
| CVE-2020-35592 | MEDIUM | 5.4 | 0.9% | Feb 18, 2021 | Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitra... |
| CVE-2020-35591 | MEDIUM | 5.4 | 1.1% | Feb 18, 2021 | Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the us... |
| CVE-2020-28499 | CRITICAL | 9.8 | 1.4% | Feb 18, 2021 | All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge . |
| CVE-2020-28491 | HIGH | 7.5 | 3.1% | Feb 18, 2021 | This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-... |
| CVE-2020-28463 | MEDIUM | 6.5 | 1.5% | Feb 18, 2021 | All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce ... |
| CVE-2020-4933 | MEDIUM | 5.4 | 0.5% | Feb 18, 2021 | IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allo... |
| CVE-2020-28496 | HIGH | 7.5 | 2.5% | Feb 18, 2021 | This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require... |
| CVE-2020-28490 | CRITICAL | 9.8 | 2.5% | Feb 18, 2021 | The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For exam... |
| CVE-2020-35577 | MEDIUM | 6.5 | 1.0% | Feb 18, 2021 | In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to ... |
| CVE-2020-29664 | HIGH | 7.8 | 1.5% | Feb 18, 2021 | A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code... |
| CVE-2020-9306 | HIGH | 8.8 | 1.2% | Feb 18, 2021 | Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi Connec... |
| CVE-2020-12878 | HIGH | 7.8 | 0.5% | Feb 18, 2021 | Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlin... |
| CVE-2020-8625 | HIGH | 8.1 | 64.2% | Feb 17, 2021 | BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a co... |
| CVE-2020-36245 | HIGH | 8.8 | 1.5% | Feb 17, 2021 | GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent.... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now