2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27818LOW3.3A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be p...
CVE-2020-25692HIGH7.5A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming ...
CVE-2020-25677MEDIUM5.5A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissi...
CVE-2020-25631MEDIUM6.1A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScr...
CVE-2020-25630HIGH7.5A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quot...
CVE-2020-25629HIGH8.8A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course manag...
CVE-2020-25628MEDIUM6.1The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 ...
CVE-2020-8566MEDIUM5.5In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets...
CVE-2020-8565MEDIUM5.5In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. ...
CVE-2020-8564MEDIUM5.5In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the...
CVE-2020-8563MEDIUM5.5In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credenti...
CVE-2020-28935MEDIUM5.5NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a...
CVE-2020-27641Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-29136. Reason: This candidate is a reservation d...
CVE-2020-29600CRITICAL9.8In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only rea...
CVE-2020-29599HIGH7.8ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a passwo...
CVE-2020-29597CRITICAL9.8IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un...
CVE-2020-17521MEDIUM5.5Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's impleme...
CVE-2020-13945MEDIUM6.5In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the ...
CVE-2020-29595CRITICAL9.8PlugIns\IDE_ACDStd.apl in ACDSee Photo Studio Studio Professional 2021 14.0 Build 1705 has a User Mode Write AV starting...
CVE-2020-26513MEDIUM5.5An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM ...
CVE-2020-26122HIGH7.2Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The...
CVE-2020-27151HIGH8.8An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries giv...
CVE-2020-9247HIGH7.8There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain c...
CVE-2020-5800CRITICAL9.8The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and ret...
CVE-2020-5799CRITICAL9.8The Eat Spray Love mobile app for both iOS and Android contains a backdoor account that, when modified, allowed privileg...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now