2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8588LOW3.5Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthoriz...
CVE-2020-18724MEDIUM5.4Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19...
CVE-2020-18723MEDIUM5.4Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code ...
CVE-2020-8294MEDIUM5.4A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack usi...
CVE-2020-25857HIGH7.5The function ClientEAPOLKeyRecvd() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to ...
CVE-2020-25856HIGH8.1The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and e...
CVE-2020-25855HIGH8.1The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and exclu...
CVE-2020-25854HIGH8.1The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and e...
CVE-2020-25853HIGH7.5The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excludi...
CVE-2020-17523CRITICAL9.8Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentica...
CVE-2020-17516HIGH7.5Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'r...
CVE-2020-35667HIGH7.5JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
CVE-2020-35482MEDIUM5.4SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
CVE-2020-35481CRITICAL9.8SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
CVE-2020-2507CRITICAL9.8The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerabili...
CVE-2020-2506CRITICAL9.8The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulne...
CVE-2020-29582MEDIUM5.3In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker wa...
CVE-2020-28895HIGH7.3In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated b...
CVE-2020-28653CRITICAL9.8Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v...
CVE-2020-28001MEDIUM5.4SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
CVE-2020-27994MEDIUM6.5SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
CVE-2020-27222HIGH7.5In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, ...
CVE-2020-25208MEDIUM5.3In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permiss...
CVE-2020-29166HIGH7.5PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote in...
CVE-2020-29165CRITICAL9.8PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotel...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now