2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-22083CRITICAL9.8jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode()...
CVE-2020-35453MEDIUM5.3HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibl...
CVE-2020-35177MEDIUM5.3HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in...
CVE-2020-29652HIGH7.5A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go all...
CVE-2020-27199HIGH7.5The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application...
CVE-2020-35123MEDIUM6.5In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in ...
CVE-2020-25011CRITICAL9.8A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Se...
CVE-2020-25010CRITICAL9.8An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers S...
CVE-2020-25096HIGH8.8LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different ro...
CVE-2020-25095HIGH8.8LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CS...
CVE-2020-25094CRITICAL9.8LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program nam...
CVE-2020-35197CRITICAL9.8The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. Sy...
CVE-2020-35196CRITICAL9.8The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password fo...
CVE-2020-35195CRITICAL9.8The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. Syst...
CVE-2020-35194Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation du...
CVE-2020-35192CRITICAL9.8The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker c...
CVE-2020-35191CRITICAL9.8The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. S...
CVE-2020-35190CRITICAL9.8The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root u...
CVE-2020-35188Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation du...
CVE-2020-35186CRITICAL9.8The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the admin...
CVE-2020-35184CRITICAL9.8The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer doc...
CVE-2020-29436MEDIUM6.5Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain ...
CVE-2020-35189CRITICAL9.8The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System u...
CVE-2020-35187CRITICAL9.8The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. Syst...
CVE-2020-35185CRITICAL9.8The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now