2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28373HIGH8.8upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overfl...
CVE-2020-28371CRITICAL9.8An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. The FileOutputStream.write() method in FileOutputStr...
CVE-2020-26168CRITICAL9.8The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x ...
CVE-2020-14189CRITICAL9.8The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to ex...
CVE-2020-14188CRITICAL9.8The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to...
CVE-2020-4759HIGH7.8IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute ...
CVE-2020-4651MEDIUM4.8IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery w...
CVE-2020-4650LOW3.3IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which c...
CVE-2020-28364MEDIUM6.1A stored cross-site scripting (XSS) vulnerability affects the Web UI in Locust before 1.3.2, if the installation violate...
CVE-2020-27977HIGH7.8CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts...
CVE-2020-26542CRITICAL9.8An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDA...
CVE-2020-23140HIGH8.1Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user...
CVE-2020-23139MEDIUM5.5Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which ...
CVE-2020-23138CRITICAL9.8An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can up...
CVE-2020-23136MEDIUM5.5Microweber v1.1.18 is affected by no session expiry after log-out.
CVE-2020-14366HIGH7.5A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible b...
CVE-2020-9300MEDIUM6.5The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, ...
CVE-2020-9299MEDIUM5.4There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description param...
CVE-2020-8276MEDIUM5.5The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the times...
CVE-2020-8268HIGH7.5Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify metho...
CVE-2020-8150MEDIUM4.1A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the in...
CVE-2020-8133MEDIUM5.3A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite...
CVE-2020-25655MEDIUM6.5An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct...
CVE-2020-24353MEDIUM6.1Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
CVE-2020-15297CRITICAL9.1Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tool...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now