2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26892 | CRITICAL | 9.8 | 2.1% | Nov 6, 2020 | The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are han... |
| CVE-2020-26521 | HIGH | 7.5 | 2.1% | Nov 6, 2020 | The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code). |
| CVE-2020-25592 | CRITICAL | 9.8 | 57.5% | Nov 6, 2020 | In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authent... |
| CVE-2020-17490 | MEDIUM | 5.5 | 0.4% | Nov 6, 2020 | The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions. |
| CVE-2020-16846 | CRITICAL | 9.8 | 99.6% | Nov 6, 2020 | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien... |
| CVE-2020-28250 | CRITICAL | 9.8 | 2.9% | Nov 6, 2020 | Cellinx NVT Web Server 5.0.0.014b.test 2019-09-05 allows a remote user to run commands as root via SetFileContent.cgi be... |
| CVE-2020-28249 | MEDIUM | 6.1 | 3.0% | Nov 6, 2020 | Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. |
| CVE-2020-28242 | MEDIUM | 6.5 | 1.5% | Nov 6, 2020 | An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x b... |
| CVE-2020-28241 | MEDIUM | 6.5 | 2.1% | Nov 6, 2020 | libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c. |
| CVE-2020-5667 | MEDIUM | 5.5 | 0.3% | Nov 6, 2020 | Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for ... |
| CVE-2020-5649 | HIGH | 7.5 | 4.1% | Nov 6, 2020 | Resource management error vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT... |
| CVE-2020-5648 | CRITICAL | 9.8 | 3.4% | Nov 6, 2020 | Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl... |
| CVE-2020-5647 | CRITICAL | 9.8 | 4.2% | Nov 6, 2020 | Improper access control vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT14... |
| CVE-2020-5646 | HIGH | 7.5 | 4.1% | Nov 6, 2020 | NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT... |
| CVE-2020-5645 | HIGH | 7.5 | 3.8% | Nov 6, 2020 | Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBD... |
| CVE-2020-5644 | CRITICAL | 9.8 | 4.5% | Nov 6, 2020 | Buffer overflow vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE... |
| CVE-2020-5643 | MEDIUM | 6.5 | 1.7% | Nov 6, 2020 | Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete... |
| CVE-2020-27347 | HIGH | 7.8 | 0.7% | Nov 6, 2020 | In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-o... |
| CVE-2020-15708 | HIGH | 7.8 | 0.4% | Nov 6, 2020 | Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker c... |
| CVE-2020-7207 | MEDIUM | 6.8 | 0.5% | Nov 5, 2020 | A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers usin... |
| CVE-2020-6877 | HIGH | 8.8 | 1.0% | Nov 5, 2020 | A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the a... |
| CVE-2020-25837 | HIGH | 7.5 | 1.0% | Nov 5, 2020 | Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerabil... |
| CVE-2020-25662 | MEDIUM | 6.5 | 1.2% | Nov 5, 2020 | A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation ha... |
| CVE-2020-25661 | HIGH | 8.8 | 1.8% | Nov 5, 2020 | A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled ... |
| CVE-2020-17510 | CRITICAL | 9.8 | 9.1% | Nov 5, 2020 | Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentica... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now