2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35512 | HIGH | 7.8 | 0.3% | Feb 15, 2021 | A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1... |
| CVE-2020-29031 | HIGH | 8.1 | 0.7% | Feb 15, 2021 | An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated ... |
| CVE-2020-29026 | MEDIUM | 6.5 | 1.5% | Feb 15, 2021 | A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated a... |
| CVE-2020-4956 | MEDIUM | 4.8 | 0.4% | Feb 15, 2021 | IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows cer... |
| CVE-2020-4955 | HIGH | 8 | 0.6% | Feb 15, 2021 | IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system,... |
| CVE-2020-4954 | MEDIUM | 5.4 | 0.5% | Feb 15, 2021 | IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, ... |
| CVE-2020-35775 | CRITICAL | 9.8 | 13.3% | Feb 15, 2021 | CITSmart before 9.1.2.23 allows LDAP Injection. |
| CVE-2020-28500 | MEDIUM | 5.3 | 7.3% | Feb 15, 2021 | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim a... |
| CVE-2020-7071 | MEDIUM | 5.3 | 3.0% | Feb 15, 2021 | In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($ur... |
| CVE-2020-29451 | MEDIUM | 4.3 | 0.8% | Feb 15, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Info... |
| CVE-2020-36237 | MEDIUM | 5.3 | 1.2% | Feb 15, 2021 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field o... |
| CVE-2020-36236 | MEDIUM | 6.1 | 1.3% | Feb 15, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2020-36235 | MEDIUM | 5.3 | 2.0% | Feb 15, 2021 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field a... |
| CVE-2020-36234 | MEDIUM | 4.8 | 1.0% | Feb 15, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2020-13949 | HIGH | 7.5 | 6.8% | Feb 12, 2021 | In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory a... |
| CVE-2020-27869 | HIGH | 8.8 | 5.1% | Feb 12, 2021 | This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Perfor... |
| CVE-2020-27868 | CRITICAL | 9.8 | 81.2% | Feb 12, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0... |
| CVE-2020-27867 | MEDIUM | 6.8 | 2.3% | Feb 12, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R602... |
| CVE-2020-27866 | HIGH | 8.8 | 8.7% | Feb 12, 2021 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020... |
| CVE-2020-27865 | HIGH | 8.8 | 2.5% | Feb 12, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1... |
| CVE-2020-27864 | HIGH | 8.8 | 9.8% | Feb 12, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1... |
| CVE-2020-27863 | MEDIUM | 6.5 | 1.0% | Feb 12, 2021 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li... |
| CVE-2020-27862 | HIGH | 8.8 | 1.4% | Feb 12, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2... |
| CVE-2020-27861 | HIGH | 8.8 | 2.0% | Feb 12, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi... |
| CVE-2020-27860 | HIGH | 7.8 | 3.6% | Feb 12, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now