2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25796HIGH7.5An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation, an unaligne...
CVE-2020-25795HIGH7.5An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, insert_from can h...
CVE-2020-25794HIGH7.5An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, clone can have a ...
CVE-2020-25793HIGH7.5An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is...
CVE-2020-25792HIGH7.5An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is...
CVE-2020-25791HIGH7.5An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is...
CVE-2020-25790HIGH7.2Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi...
CVE-2020-25789MEDIUM6.1An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript in...
CVE-2020-25788HIGH8.1An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mish...
CVE-2020-25787CRITICAL9.8An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting...
CVE-2020-25786MEDIUM6.1webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header....
CVE-2020-5421MEDIUM6.5In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versio...
CVE-2020-8253HIGH7.5Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe...
CVE-2020-8252HIGH7.8The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined th...
CVE-2020-8251HIGH7.5Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can m...
CVE-2020-8247HIGH8.8Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix AD...
CVE-2020-8246HIGH7.5Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix AD...
CVE-2020-8245MEDIUM6.1Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1...
CVE-2020-8237HIGH7.5Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
CVE-2020-8225HIGH7.5A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies ...
CVE-2020-8201HIGH7.4Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspec...
CVE-2020-8200MEDIUM6.5Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Mi...
CVE-2020-8158CRITICAL9.8Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties...
CVE-2020-11861HIGH7.8Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior t...
CVE-2020-9084MEDIUM6.5Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now