2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6425 | MEDIUM | 5.4 | 1.2% | Mar 23, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced ... |
| CVE-2020-8497 | MEDIUM | 5.3 | 5.3% | Mar 23, 2020 | In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format an... |
| CVE-2020-1951 | MEDIUM | 5.5 | 2.7% | Mar 23, 2020 | A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. |
| CVE-2020-1950 | MEDIUM | 5.5 | 2.6% | Mar 23, 2020 | A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23... |
| CVE-2020-10660 | MEDIUM | 5.3 | 0.8% | Mar 23, 2020 | HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Gro... |
| CVE-2020-10821 | MEDIUM | 4.8 | 73.6% | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter. |
| CVE-2020-10820 | MEDIUM | 4.8 | 30.1% | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter. |
| CVE-2020-10819 | MEDIUM | 4.8 | 73.8% | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter. |
| CVE-2020-10812 | MEDIUM | 5.5 | 1.5% | Mar 22, 2020 | An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() locate... |
| CVE-2020-10811 | MEDIUM | 5.5 | 1.4% | Mar 22, 2020 | An issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5O__layout_decode(... |
| CVE-2020-10810 | MEDIUM | 5.5 | 1.4% | Mar 22, 2020 | An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5AC_unpin_entry() loc... |
| CVE-2020-10809 | MEDIUM | 5.5 | 1.5% | Mar 22, 2020 | An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located... |
| CVE-2020-10807 | MEDIUM | 5.3 | 1.4% | Mar 22, 2020 | auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in... |
| CVE-2020-10803 | MEDIUM | 5.4 | 1.6% | Mar 22, 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code c... |
| CVE-2020-8140 | MEDIUM | 6.7 | 0.7% | Mar 20, 2020 | A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client wit... |
| CVE-2020-8139 | MEDIUM | 6.5 | 1.5% | Mar 20, 2020 | A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be do... |
| CVE-2020-8138 | MEDIUM | 6.5 | 1.4% | Mar 20, 2020 | A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side ... |
| CVE-2020-10194 | MEDIUM | 6.5 | 1.2% | Mar 20, 2020 | cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any ... |
| CVE-2020-8883 | MEDIUM | 4.3 | 8.4% | Mar 20, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P... |
| CVE-2020-8879 | MEDIUM | 4.3 | 8.2% | Mar 20, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P... |
| CVE-2020-8877 | MEDIUM | 4.3 | 8.2% | Mar 20, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P... |
| CVE-2020-10558 | MEDIUM | 6.5 | 2.6% | Mar 20, 2020 | The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to... |
| CVE-2020-1878 | MEDIUM | 5.5 | 0.2% | Mar 20, 2020 | Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C0... |
| CVE-2020-1796 | MEDIUM | 6.6 | 0.2% | Mar 20, 2020 | There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorizat... |
| CVE-2020-1794 | MEDIUM | 4.6 | 0.2% | Mar 20, 2020 | There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient auth... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now