2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14299MEDIUM6.5A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegat...
CVE-2020-14144HIGH7.2The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer envir...
CVE-2020-26893HIGH7.8An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (runn...
CVE-2020-26943CRITICAL9.9An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blaza...
CVE-2020-26584MEDIUM6.1An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog...
CVE-2020-26583MEDIUM6.1An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (...
CVE-2020-25829HIGH7.5An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacke...
CVE-2020-24352MEDIUM5.5An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementa...
CVE-2020-27176CRITICAL9.6Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a du...
CVE-2020-27174HIGH7.5In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage w...
CVE-2020-27173HIGH7.5In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input so...
CVE-2020-27163MEDIUM6.1phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter.
CVE-2020-14185MEDIUM5.3Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permission...
CVE-2020-7591HIGH8.8A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow a...
CVE-2020-1777MEDIUM5.3Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as ...
CVE-2020-15794MEDIUM4.3A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show th...
CVE-2020-15793MEDIUM5.4A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Optio...
CVE-2020-15792MEDIUM4.3A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input vali...
CVE-2020-12504CRITICAL9.8Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv...
CVE-2020-12503HIGH7.2Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv...
CVE-2020-12502HIGH8.8Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv...
CVE-2020-12501CRITICAL9.8Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv...
CVE-2020-12500CRITICAL9.8Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv...
CVE-2020-25859MEDIUM6.7The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() ca...
CVE-2020-25858HIGH7.5The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not val...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now