2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26892CRITICAL9.8The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are han...
CVE-2020-26521HIGH7.5The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
CVE-2020-25592CRITICAL9.8In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authent...
CVE-2020-17490MEDIUM5.5The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
CVE-2020-16846CRITICAL9.8An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien...
CVE-2020-28250CRITICAL9.8Cellinx NVT Web Server 5.0.0.014b.test 2019-09-05 allows a remote user to run commands as root via SetFileContent.cgi be...
CVE-2020-28249MEDIUM6.1Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.
CVE-2020-28242MEDIUM6.5An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x b...
CVE-2020-28241MEDIUM6.5libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.
CVE-2020-5667MEDIUM5.5Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for ...
CVE-2020-5649HIGH7.5Resource management error vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT...
CVE-2020-5648CRITICAL9.8Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl...
CVE-2020-5647CRITICAL9.8Improper access control vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT14...
CVE-2020-5646HIGH7.5NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT...
CVE-2020-5645HIGH7.5Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBD...
CVE-2020-5644CRITICAL9.8Buffer overflow vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE...
CVE-2020-5643MEDIUM6.5Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete...
CVE-2020-27347HIGH7.8In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-o...
CVE-2020-15708HIGH7.8Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker c...
CVE-2020-7207MEDIUM6.8A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers usin...
CVE-2020-6877HIGH8.8A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the a...
CVE-2020-25837HIGH7.5Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerabil...
CVE-2020-25662MEDIUM6.5A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation ha...
CVE-2020-25661HIGH8.8A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled ...
CVE-2020-17510CRITICAL9.8Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentica...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now