2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-22083 | CRITICAL | 9.8 | 6.1% | Dec 17, 2020 | jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode()... |
| CVE-2020-35453 | MEDIUM | 5.3 | 0.8% | Dec 17, 2020 | HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibl... |
| CVE-2020-35177 | MEDIUM | 5.3 | 1.3% | Dec 17, 2020 | HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in... |
| CVE-2020-29652 | HIGH | 7.5 | 3.2% | Dec 17, 2020 | A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go all... |
| CVE-2020-27199 | HIGH | 7.5 | 2.9% | Dec 17, 2020 | The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application... |
| CVE-2020-35123 | MEDIUM | 6.5 | 1.5% | Dec 17, 2020 | In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in ... |
| CVE-2020-25011 | CRITICAL | 9.8 | 1.6% | Dec 17, 2020 | A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Se... |
| CVE-2020-25010 | CRITICAL | 9.8 | 2.4% | Dec 17, 2020 | An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers S... |
| CVE-2020-25096 | HIGH | 8.8 | 1.0% | Dec 17, 2020 | LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different ro... |
| CVE-2020-25095 | HIGH | 8.8 | 1.0% | Dec 17, 2020 | LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CS... |
| CVE-2020-25094 | CRITICAL | 9.8 | 3.1% | Dec 17, 2020 | LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program nam... |
| CVE-2020-35197 | CRITICAL | 9.8 | 2.1% | Dec 17, 2020 | The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. Sy... |
| CVE-2020-35196 | CRITICAL | 9.8 | 2.1% | Dec 17, 2020 | The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password fo... |
| CVE-2020-35195 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. Syst... |
| CVE-2020-35194 | — | — | — | Dec 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation du... |
| CVE-2020-35192 | CRITICAL | 9.8 | 2.9% | Dec 17, 2020 | The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker c... |
| CVE-2020-35191 | CRITICAL | 9.8 | 4.6% | Dec 17, 2020 | The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. S... |
| CVE-2020-35190 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root u... |
| CVE-2020-35188 | — | — | — | Dec 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation du... |
| CVE-2020-35186 | CRITICAL | 9.8 | 2.9% | Dec 17, 2020 | The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the admin... |
| CVE-2020-35184 | CRITICAL | 9.8 | 3.0% | Dec 17, 2020 | The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer doc... |
| CVE-2020-29436 | MEDIUM | 6.5 | 1.4% | Dec 17, 2020 | Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain ... |
| CVE-2020-35189 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System u... |
| CVE-2020-35187 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. Syst... |
| CVE-2020-35185 | CRITICAL | 9.8 | 2.8% | Dec 17, 2020 | The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now