2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9049MEDIUM5.3A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could ...
CVE-2020-4718MEDIUM5.4IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerabili...
CVE-2020-4701HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflo...
CVE-2020-28054HIGH7.5JamoDat TSMManager Collector version up to 6.5.0.21 is vulnerable to an Authorization Bypass because the Collector compo...
CVE-2020-11831CRITICAL9.8OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovo...
CVE-2020-11830CRITICAL9.8QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2....
CVE-2020-11829CRITICAL9.8Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros....
CVE-2020-15710MEDIUM6.1Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. ...
CVE-2020-8279HIGH7.4Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-mid...
CVE-2020-8278MEDIUM5.3Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
CVE-2020-8277HIGH7.5A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial...
CVE-2020-5947MEDIUM4.3In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequenc...
CVE-2020-13360Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-13359HIGH7.6The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malici...
CVE-2020-13356HIGH8.2An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request cou...
CVE-2020-13355HIGH8.1An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS...
CVE-2020-12593HIGH7.5Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a ...
CVE-2020-26226HIGH8.1In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` c...
CVE-2020-26215MEDIUM6.1Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook serve...
CVE-2020-22723MEDIUM6.1A cross-site scripting (XSS) vulnerability in Beijing Liangjing Zhicheng Technology Co., Ltd ljcmsshop version 1.14 allo...
CVE-2020-15300MEDIUM6.1SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
CVE-2020-14208MEDIUM5.4SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerabi...
CVE-2020-13799MEDIUM6.8Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specifie...
CVE-2020-25454MEDIUM5.4Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the...
CVE-2020-15301HIGH7.8SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Lead...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now