2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-7904HIGH7.4In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
CVE-2020-1931HIGH8.1A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.c...
CVE-2020-1930HIGH8.1A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuratio...
CVE-2020-8442HIGH8.8In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ...
CVE-2020-8438HIGH7.2Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hid...
CVE-2020-3719HIGH7.5Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql inject...
CVE-2020-3714HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-3713HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-3712HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-3711HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-3710HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-8416HIGH7.5IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to th...
CVE-2020-2108HIGH7.6Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can b...
CVE-2020-2099HIGH8.6Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent ...
CVE-2020-7965HIGH8.8flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receivin...
CVE-2020-8428HIGH7.1fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a...
CVE-2020-8424HIGH8.8Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php...
CVE-2020-5227HIGH7.5Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supp...
CVE-2020-5215HIGH7.5In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation...
CVE-2020-8420HIGH8.8An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates cause...
CVE-2020-8419HIGH8.8An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause ...
CVE-2020-8417HIGH8.8The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import me...
CVE-2020-8112HIGH8.8opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in th...
CVE-2020-5210HIGH7.8In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a cr...
CVE-2020-5209HIGH7.8In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or re...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now