2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10007MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A malicious app...
CVE-2020-10006MEDIUM5.5This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.0.1. A malicious applicatio...
CVE-2020-10004HIGH7.8A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iP...
CVE-2020-10003HIGH7.8An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization...
CVE-2020-10002MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iO...
CVE-2020-29602CRITICAL9.8The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System us...
CVE-2020-29601CRITICAL9.8The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notar...
CVE-2020-29581CRITICAL9.8The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped d...
CVE-2020-29580CRITICAL9.8The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker c...
CVE-2020-29579CRITICAL9.8The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Exp...
CVE-2020-29577CRITICAL9.8The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker ...
CVE-2020-29576CRITICAL9.8The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop D...
CVE-2020-29575CRITICAL9.8The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. System...
CVE-2020-29564CRITICAL9.8The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul ...
CVE-2020-1971MEDIUM5.9The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known...
CVE-2020-29578CRITICAL9.8The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems u...
CVE-2020-26255CRITICAL9.1Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with...
CVE-2020-26254HIGH7.7omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before vers...
CVE-2020-25955MEDIUM5.4SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS)...
CVE-2020-29540HIGH7.5API calls in the Translation API feature in Systran Pure Neural Server before 9.7.0 allow a threat actor to use the Syst...
CVE-2020-29539MEDIUM5.4A Cross-Site Scripting (XSS) issue in WebUI Translation in Systran Pure Neural Server before 9.7.0 allows a threat actor...
CVE-2020-25889CRITICAL9.8Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injec...
CVE-2020-17531CRITICAL9.8A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp...
CVE-2020-26253MEDIUM5.9Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulne...
CVE-2020-27822MEDIUM5.9A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now