2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6425MEDIUM5.4Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced ...
CVE-2020-8497MEDIUM5.3In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format an...
CVE-2020-1951MEDIUM5.5A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
CVE-2020-1950MEDIUM5.5A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23...
CVE-2020-10660MEDIUM5.3HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Gro...
CVE-2020-10821MEDIUM4.8Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
CVE-2020-10820MEDIUM4.8Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
CVE-2020-10819MEDIUM4.8Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.
CVE-2020-10812MEDIUM5.5An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() locate...
CVE-2020-10811MEDIUM5.5An issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5O__layout_decode(...
CVE-2020-10810MEDIUM5.5An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5AC_unpin_entry() loc...
CVE-2020-10809MEDIUM5.5An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located...
CVE-2020-10807MEDIUM5.3auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in...
CVE-2020-10803MEDIUM5.4In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code c...
CVE-2020-8140MEDIUM6.7A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client wit...
CVE-2020-8139MEDIUM6.5A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be do...
CVE-2020-8138MEDIUM6.5A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side ...
CVE-2020-10194MEDIUM6.5cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any ...
CVE-2020-8883MEDIUM4.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P...
CVE-2020-8879MEDIUM4.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P...
CVE-2020-8877MEDIUM4.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P...
CVE-2020-10558MEDIUM6.5The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to...
CVE-2020-1878MEDIUM5.5Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C0...
CVE-2020-1796MEDIUM6.6There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorizat...
CVE-2020-1794MEDIUM4.6There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient auth...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now