2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-17519HIGH7.5A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file...
CVE-2020-17518HIGH7.5Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the l...
CVE-2020-36158MEDIUM6.7mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might ...
CVE-2020-5361HIGH7.6Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist...
CVE-2020-29498MEDIUM6.1Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attack...
CVE-2020-29497MEDIUM5.4Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authentic...
CVE-2020-29496MEDIUM4.8Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authentic...
CVE-2020-29492CRITICAL10Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate...
CVE-2020-29491HIGH8.6Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate...
CVE-2020-26297MEDIUM6.1mdBook is a utility to create modern online books from Markdown files and is written in Rust. In mdBook before version 0...
CVE-2020-26294MEDIUM5.3Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler ...
CVE-2020-26293MEDIUM6.1HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. ...
CVE-2020-36157CRITICAL9.8An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat...
CVE-2020-36156HIGH8.8An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalatio...
CVE-2020-36155CRITICAL9.8An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat...
CVE-2020-35219CRITICAL9.8The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin passw...
CVE-2020-26292CRITICAL9.8Creeper is an experimental dynamic, interpreted language. The binary release of Creeper Interpreter 1.1.3 contains poten...
CVE-2020-36154HIGH7.8The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMD...
CVE-2020-25275HIGH7.5Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafte...
CVE-2020-24386MEDIUM6.8An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernatio...
CVE-2020-17537Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-17536Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-17535Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-36112CRITICAL9.8CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pub...
CVE-2020-35507MEDIUM5.5There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now