2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29362 | MEDIUM | 5.3 | 2.3% | Dec 16, 2020 | An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC ... |
| CVE-2020-29361 | HIGH | 7.5 | 3.4% | Dec 16, 2020 | An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array ... |
| CVE-2020-25619 | MEDIUM | 4.4 | 0.4% | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channe... |
| CVE-2020-25618 | HIGH | 8.8 | 2.6% | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because ... |
| CVE-2020-25617 | HIGH | 8.8 | 3.2% | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Trave... |
| CVE-2020-28458 | HIGH | 7.3 | 3.7% | Dec 16, 2020 | All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.i... |
| CVE-2020-5683 | HIGH | 7.5 | 3.0% | Dec 16, 2020 | Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1... |
| CVE-2020-5682 | HIGH | 7.5 | 2.0% | Dec 16, 2020 | Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series)... |
| CVE-2020-35476 | CRITICAL | 9.8 | 85.3% | Dec 16, 2020 | A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. Th... |
| CVE-2020-26273 | MEDIUM | 5.2 | 0.9% | Dec 16, 2020 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before versio... |
| CVE-2020-26259 | MEDIUM | 6.8 | 81.0% | Dec 16, 2020 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to... |
| CVE-2020-26258 | HIGH | 7.7 | 81.4% | Dec 16, 2020 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Fo... |
| CVE-2020-35469 | CRITICAL | 9.8 | 2.1% | Dec 16, 2020 | The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed u... |
| CVE-2020-35468 | CRITICAL | 9.8 | 2.1% | Dec 16, 2020 | The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected vers... |
| CVE-2020-35193 | CRITICAL | 9.8 | 2.1% | Dec 16, 2020 | The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System us... |
| CVE-2020-35467 | CRITICAL | 9.8 | 2.2% | Dec 15, 2020 | The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affe... |
| CVE-2020-35466 | CRITICAL | 9.8 | 2.1% | Dec 15, 2020 | The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affect... |
| CVE-2020-35465 | — | — | — | Dec 15, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-35464 | CRITICAL | 9.8 | 2.1% | Dec 15, 2020 | Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using ... |
| CVE-2020-35463 | CRITICAL | 9.8 | 2.1% | Dec 15, 2020 | Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed usin... |
| CVE-2020-35462 | CRITICAL | 9.8 | 2.1% | Dec 15, 2020 | Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using aff... |
| CVE-2020-35122 | HIGH | 7.5 | 0.8% | Dec 15, 2020 | An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could by... |
| CVE-2020-35121 | HIGH | 8.8 | 1.0% | Dec 15, 2020 | An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could in... |
| CVE-2020-29663 | CRITICAL | 9.1 | 1.6% | Dec 15, 2020 | Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically b... |
| CVE-2020-35416 | MEDIUM | 6.1 | 2.7% | Dec 15, 2020 | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now