2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29239MEDIUM6.1Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result i...
CVE-2020-25266MEDIUM5.5AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it w...
CVE-2020-25265MEDIUM6.5AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by provid...
CVE-2020-13956MEDIUM5.3Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request U...
CVE-2020-28273CRITICAL9.8Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service ...
CVE-2020-28272CRITICAL9.8Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service ...
CVE-2020-25638HIGH7.4A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementatio...
CVE-2020-14369MEDIUM6.3This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to ...
CVE-2020-12524HIGH7.5Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W ...
CVE-2020-29458HIGH8.8Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
CVE-2020-29456MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrar...
CVE-2020-5423HIGH7.5CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticat...
CVE-2020-29454MEDIUM4.3Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Ap...
CVE-2020-7199CRITICAL9.8A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr...
CVE-2020-6018CRITICAL9.8Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_D...
CVE-2020-4102MEDIUM6.7HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successfu...
CVE-2020-27816MEDIUM6.1The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it i...
CVE-2020-27813HIGH7.5An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An att...
CVE-2020-25723LOW3.2A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB reques...
CVE-2020-25704MEDIUM5.5A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET...
CVE-2020-25656MEDIUM4.1A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKB...
CVE-2020-14383MEDIUM6.5A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC s...
CVE-2020-14305HIGH8.1An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functiona...
CVE-2020-14260CRITICAL9.8HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successf...
CVE-2020-26250MEDIUM6.3OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now