2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29362MEDIUM5.3An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC ...
CVE-2020-29361HIGH7.5An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array ...
CVE-2020-25619MEDIUM4.4An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channe...
CVE-2020-25618HIGH8.8An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because ...
CVE-2020-25617HIGH8.8An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Trave...
CVE-2020-28458HIGH7.3All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.i...
CVE-2020-5683HIGH7.5Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1...
CVE-2020-5682HIGH7.5Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series)...
CVE-2020-35476CRITICAL9.8A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. Th...
CVE-2020-26273MEDIUM5.2osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before versio...
CVE-2020-26259MEDIUM6.8XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to...
CVE-2020-26258HIGH7.7XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Fo...
CVE-2020-35469CRITICAL9.8The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed u...
CVE-2020-35468CRITICAL9.8The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected vers...
CVE-2020-35193CRITICAL9.8The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System us...
CVE-2020-35467CRITICAL9.8The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affe...
CVE-2020-35466CRITICAL9.8The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affect...
CVE-2020-35465Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-35464CRITICAL9.8Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using ...
CVE-2020-35463CRITICAL9.8Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed usin...
CVE-2020-35462CRITICAL9.8Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using aff...
CVE-2020-35122HIGH7.5An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could by...
CVE-2020-35121HIGH8.8An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could in...
CVE-2020-29663CRITICAL9.1Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically b...
CVE-2020-35416MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now