2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6060HIGH7.5A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially ...
CVE-2020-6059HIGH8.2An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A ...
CVE-2020-7221HIGH7.8mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root becau...
CVE-2020-4163HIGH7.2IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user...
CVE-2020-3938HIGH7.5SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to laun...
CVE-2020-3937HIGH7.5SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries ...
CVE-2020-8545HIGH7.5Global.py in AIL framework 2.8 allows path traversal.
CVE-2020-3927HIGH7.5An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific ...
CVE-2020-3926HIGH7.5An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific ...
CVE-2020-3925HIGH8.8A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long ...
CVE-2020-7914HIGH7.5In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over t...
CVE-2020-7219HIGH7.5HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were suscepti...
CVE-2020-7218HIGH7.5HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptib...
CVE-2020-5232HIGH8.7A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ...
CVE-2020-8495HIGH7.5In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se...
CVE-2020-8494HIGH8.8In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser se...
CVE-2020-5230HIGH7.5Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be ...
CVE-2020-5222HIGH8.8Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an add...
CVE-2020-5229HIGH8.1Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthe...
CVE-2020-5228HIGH7.5Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH ...
CVE-2020-8093HIGH7.8A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a li...
CVE-2020-3147HIGH7.5A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause ...
CVE-2020-7909HIGH7.5In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
CVE-2020-7906HIGH7.5In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows instal...
CVE-2020-7905HIGH7.5Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now