2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6112HIGH7.8An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc....
CVE-2020-13948HIGH8.8While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests v...
CVE-2020-8028CRITICAL9.3A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Se...
CVE-2020-14181MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor...
CVE-2020-24377CRITICAL9.6A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
CVE-2020-24376CRITICAL9.6A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2....
CVE-2020-24374CRITICAL9.6A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
CVE-2020-24373HIGH8.8A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
CVE-2020-20406MEDIUM5.4A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 ...
CVE-2020-16233HIGH7.5An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packe...
CVE-2020-14519HIGH7.5This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are a...
CVE-2020-14517CRITICAL9.8Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 ...
CVE-2020-14515HIGH7.5CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in ...
CVE-2020-14513HIGH7.5CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted licen...
CVE-2020-14509CRITICAL9.8Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mecha...
CVE-2020-6781HIGH7.4Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17...
CVE-2020-6146HIGH8.8An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.3...
CVE-2020-1694MEDIUM4.9A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-au...
CVE-2020-13259HIGH8.8A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauth...
CVE-2020-10718HIGH7.5A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed ...
CVE-2020-25040HIGH8.8Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit contain...
CVE-2020-25039HIGH8.1Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namesp...
CVE-2020-25015MEDIUM6.5A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally...
CVE-2020-14348MEDIUM4.3It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the us...
CVE-2020-14306HIGH8.8An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions thr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now