2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28483HIGH7.1This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's ...
CVE-2020-28452HIGH8.8This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package c...
CVE-2020-25687MEDIUM5.9A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is e...
CVE-2020-25686LOW3.7A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending ...
CVE-2020-25682HIGH8.1A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names...
CVE-2020-25681HIGH8.1A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorte...
CVE-2020-35272MEDIUM4.8Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in t...
CVE-2020-35271MEDIUM4.8Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in t...
CVE-2020-25685LOW3.7A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward....
CVE-2020-25684LOW3.7A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forw...
CVE-2020-25683MEDIUM5.9A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is e...
CVE-2020-20949MEDIUM5.9Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for S...
CVE-2020-14360HIGH7.8A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead ...
CVE-2020-4983HIGH7.8IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to subm...
CVE-2020-4921HIGH8.8IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL s...
CVE-2020-4887MEDIUM5.5IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to cre...
CVE-2020-4688HIGH7.8IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unpri...
CVE-2020-14756CRITICAL9.8Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio...
CVE-2020-35217HIGH8.8Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF toke...
CVE-2020-27852MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allo...
CVE-2020-27851MEDIUM5.4Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketg...
CVE-2020-27850MEDIUM4.8A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 al...
CVE-2020-13134MEDIUM4.8Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires a...
CVE-2020-13133MEDIUM6.1Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires a...
CVE-2020-25385MEDIUM6.1Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapsho...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now