2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9106MEDIUM4.6HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not su...
CVE-2020-9091MEDIUM5.5Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an out-of-bounds read and write vulnerability. Some func...
CVE-2020-9090HIGH7.8FusionAccess version 6.5.1 has an improper authorization vulnerability. A command is authorized with incorrect privilege...
CVE-2020-9087MEDIUM5.5Taurus-AL00A version 10.0.0.1(C00E1R1P1) has an out-of-bounds read vulnerability in XFRM module. An authenticated, local...
CVE-2020-7811HIGH7.8Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker a...
CVE-2020-4741MEDIUM5.4IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows ...
CVE-2020-4740MEDIUM5.2IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to HTML injection. A remote attacker could inject maliciou...
CVE-2020-4689MEDIUM6.8IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands...
CVE-2020-4681MEDIUM5.4IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2020-4680MEDIUM5.4IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2020-4679MEDIUM4.8IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2020-4678MEDIUM4.9IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would n...
CVE-2020-4388HIGH8.2IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a...
CVE-2020-4302HIGH7.8IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CS...
CVE-2020-26869HIGH7.5ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to ac...
CVE-2020-26868HIGH7.5ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an una...
CVE-2020-26867CRITICAL9.8ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may al...
CVE-2020-13943MEDIUM4.3If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded t...
CVE-2020-13341MEDIUM4.9An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permissi...
CVE-2020-4781MEDIUM6.5An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 ...
CVE-2020-4780MEDIUM5.3OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Managem...
CVE-2020-4779HIGH8.1A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specia...
CVE-2020-4778HIGH7.5IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which les...
CVE-2020-4776HIGH7.5A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remo...
CVE-2020-4775MEDIUM5.4A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnera...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now