2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-14061HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-10752HIGH7.5A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into t...
CVE-2020-14004HIGH7.8An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd servi...
CVE-2020-9645HIGH7.5Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Success...
CVE-2020-9643HIGH7.5Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful ex...
CVE-2020-9636HIGH8.8Adobe Framemaker versions 2019.0.5 and below have a memory corruption vulnerability. Successful exploitation could lead ...
CVE-2020-9635HIGH8.8Adobe Framemaker versions 2019.0.5 and below have an out-of-bounds write vulnerability. Successful exploitation could le...
CVE-2020-9634HIGH8.8Adobe Framemaker versions 2019.0.5 and below have an out-of-bounds write vulnerability. Successful exploitation could le...
CVE-2020-14048HIGH7.5Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the install...
CVE-2020-4045HIGH7.5SSB-DB version 20.0.0 has an information disclosure vulnerability. The get() method is supposed to only decrypt messages...
CVE-2020-13250HIGH7.5HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching f...
CVE-2020-13170HIGH7.5HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data cen...
CVE-2020-12758HIGH7.5HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Intro...
CVE-2020-12725HIGH7.2Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-...
CVE-2020-5411HIGH8.1When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary...
CVE-2020-11614HIGH8.1Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Addition...
CVE-2020-11613HIGH7.8Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions b...
CVE-2020-0233HIGH7.8In main of main.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of...
CVE-2020-0219HIGH7.8In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of ...
CVE-2020-0218HIGH7In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a rac...
CVE-2020-0216HIGH7.8In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. ...
CVE-2020-0215HIGH7.8In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypas...
CVE-2020-0214HIGH7.5In ce_t4t_process_select_file_cmd of ce_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check....
CVE-2020-0210HIGH7.8In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This c...
CVE-2020-0209HIGH7.8In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalatio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now