2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-0026HIGH7.8In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to ...
CVE-2020-0022HIGH8.8In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds cal...
CVE-2020-0015HIGH7.8In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious...
CVE-2020-5239HIGH8.8In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full a...
CVE-2020-1977HIGH8.8Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated att...
CVE-2020-1975HIGH8.8Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authentica...
CVE-2020-5399HIGH7.4Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TL...
CVE-2020-8950HIGH7.8The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of p...
CVE-2020-6192HIGH7.2SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root ...
CVE-2020-6191HIGH7.2SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with ro...
CVE-2020-6188HIGH8.8VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700,...
CVE-2020-6186HIGH7.5SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentica...
CVE-2020-8949HIGH8.8Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572,...
CVE-2020-8947HIGH7.2functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac...
CVE-2020-8946HIGH8.8Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacter...
CVE-2020-8945HIGH7.5The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container ...
CVE-2020-7046HIGH7.5lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command paramet...
CVE-2020-8815HIGH7.5Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to ...
CVE-2020-8595HIGH7.3Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. Th...
CVE-2020-2123HIGH8.8Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary typ...
CVE-2020-2121HIGH8.8Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiatio...
CVE-2020-2120HIGH8.8Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2116HIGH8.8A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attack...
CVE-2020-2115HIGH8.8Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2114HIGH7.5Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenk...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now