2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35512HIGH7.8A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1...
CVE-2020-29031HIGH8.1An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated ...
CVE-2020-29026MEDIUM6.5A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated a...
CVE-2020-4956MEDIUM4.8IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows cer...
CVE-2020-4955HIGH8IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system,...
CVE-2020-4954MEDIUM5.4IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, ...
CVE-2020-35775CRITICAL9.8CITSmart before 9.1.2.23 allows LDAP Injection.
CVE-2020-28500MEDIUM5.3Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim a...
CVE-2020-7071MEDIUM5.3In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($ur...
CVE-2020-29451MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Info...
CVE-2020-36237MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field o...
CVE-2020-36236MEDIUM6.1Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2020-36235MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field a...
CVE-2020-36234MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2020-13949HIGH7.5In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory a...
CVE-2020-27869HIGH8.8This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Perfor...
CVE-2020-27868CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0...
CVE-2020-27867MEDIUM6.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R602...
CVE-2020-27866HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020...
CVE-2020-27865HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1...
CVE-2020-27864HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1...
CVE-2020-27863MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li...
CVE-2020-27862HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2...
CVE-2020-27861HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi...
CVE-2020-27860HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now