2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16109Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-16108Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-16107Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-16106Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-16105Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-4967MEDIUM4.3IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used ...
CVE-2020-4820MEDIUM6.1IBM Cloud Pak for Security (CP4S) 1.4.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2020-4816MEDIUM5.9IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the f...
CVE-2020-4815MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response h...
CVE-2020-4628MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when...
CVE-2020-36012MEDIUM4.8Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary ...
CVE-2020-23776HIGH7.5A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vu...
CVE-2020-23774MEDIUM6.1A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be execute...
CVE-2020-27295HIGH7.5The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-serv...
CVE-2020-27299CRITICAL9.1The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitiv...
CVE-2020-27297CRITICAL9.8The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory wit...
CVE-2020-27274HIGH7.5Some parsing functions in the affected product do not check the return value of malloc and the thread handling the messa...
CVE-2020-13582HIGH7.5A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafte...
CVE-2020-9492HIGH8.8In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO auth...
CVE-2020-8295HIGH7.5A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password...
CVE-2020-8293MEDIUM6.5A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in wo...
CVE-2020-8292MEDIUM5.4Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop fun...
CVE-2020-8288MEDIUM5.4The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability...
CVE-2020-6780MEDIUM4.9Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 ...
CVE-2020-6779CRITICAL10Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including ver...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now