2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26061HIGH7.5ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerabili...
CVE-2020-25635MEDIUM5.5A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after pl...
CVE-2020-12302HIGH7.8Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user...
CVE-2020-0571MEDIUM5.5Improper conditions check in BIOS firmware for 8th Generation Intel(R) Core(TM) Processors and Intel(R) Pentium(R) Silve...
CVE-2020-25636HIGH7.1A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file t...
CVE-2020-26166MEDIUM5.4The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attacker...
CVE-2020-7709HIGH7.2This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
CVE-2020-25776HIGH7.8Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an atta...
CVE-2020-5989MEDIUM5.5NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it can dereference a NULL pointer, whic...
CVE-2020-5988HIGH7.1NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which allocated memory can be freed twice, wh...
CVE-2020-5987HIGH7.8NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which guest-supplied parameters remain writabl...
CVE-2020-5986MEDIUM5.5NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, wh...
CVE-2020-5985HIGH7.1NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, ...
CVE-2020-5984HIGH7.8NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which it may have the use-after-free vulnerabi...
CVE-2020-5983HIGH7.1NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin and the host driver kernel module, in which the p...
CVE-2020-26527CRITICAL9.8An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random or...
CVE-2020-15234MEDIUM4.8ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 ...
CVE-2020-15233MEDIUM4.8ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before versio...
CVE-2020-26526MEDIUM5.3An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. Th...
CVE-2020-26525CRITICAL9.1Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the databas...
CVE-2020-24397HIGH7.2An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled se...
CVE-2020-15589HIGH8.1A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the...
CVE-2020-15232CRITICAL9.1In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
CVE-2020-15231MEDIUM6.1In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
CVE-2020-13338MEDIUM5.4An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripti...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now