2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4774MEDIUM5.4An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling ...
CVE-2020-4773MEDIUM6.5A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which...
CVE-2020-4772HIGH8.1An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A ...
CVE-2020-4699MEDIUM5.3IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin...
CVE-2020-4661MEDIUM5.3IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin...
CVE-2020-4660MEDIUM5.3IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin...
CVE-2020-5143MEDIUM5.3SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username...
CVE-2020-5142MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated a...
CVE-2020-5141MEDIUM6.5A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firew...
CVE-2020-5140HIGH7.5A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSL...
CVE-2020-5139HIGH7.5A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due ...
CVE-2020-5138HIGH7.5A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) o...
CVE-2020-5137HIGH7.5A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on ...
CVE-2020-5136MEDIUM6.5A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-...
CVE-2020-5135CRITICAL9.8A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially exe...
CVE-2020-5134MEDIUM6.5A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a fire...
CVE-2020-5133HIGH7.5A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, w...
CVE-2020-14184MEDIUM5.4Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Sit...
CVE-2020-26948CRITICAL9.8Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
CVE-2020-26947HIGH7.8monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead o...
CVE-2020-26945HIGH8.1MyBatis before 3.5.6 mishandles deserialization of object streams.
CVE-2020-26935CRITICAL9.8An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerabili...
CVE-2020-26934MEDIUM6.1phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
CVE-2020-26932MEDIUM4.3debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whe...
CVE-2020-9105MEDIUM6.7Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now