2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15437MEDIUM4.4The Linux kernel before version 5.8 is vulnerable to a NULL pointer dereference in drivers/tty/serial/8250/8250_core.c:s...
CVE-2020-15436MEDIUM6.7Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or c...
CVE-2020-28927MEDIUM6.1There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user secti...
CVE-2020-15249MEDIUM5.4October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version...
CVE-2020-15248MEDIUM4.2October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version...
CVE-2020-15247MEDIUM5.2October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version...
CVE-2020-15246HIGH7.5October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version...
CVE-2020-7927MEDIUM6.5Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key ...
CVE-2020-28896MEDIUM5.3Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's ini...
CVE-2020-28864CRITICAL9.8Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspe...
CVE-2020-26239MEDIUM5.4Scratch Addons is a WebExtension that supports both Chrome and Firefox. Scratch Addons before version 1.3.2 is vulnerabl...
CVE-2020-7928MEDIUM6.5A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing speciall...
CVE-2020-6939CRITICAL9.8Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users...
CVE-2020-4854CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key...
CVE-2020-4783MEDIUM5.9IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by...
CVE-2020-4771MEDIUM5.3IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attack...
CVE-2020-12352MEDIUM6.5Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja...
CVE-2020-12351HIGH8.8Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a...
CVE-2020-0569MEDIUM5.7Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potential...
CVE-2020-7777HIGH7.2This affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript...
CVE-2020-28421HIGH7.8CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that ...
CVE-2020-1778MEDIUM4.3When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is se...
CVE-2020-7926MEDIUM6.5A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which vio...
CVE-2020-7925HIGH7.5Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthent...
CVE-2020-28053MEDIUM6.5HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now