2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13928MEDIUM6.1Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitize...
CVE-2020-10748MEDIUM6.1A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circ...
CVE-2020-10715MEDIUM4.3A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft ...
CVE-2020-3990MEDIUM6.5VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerabil...
CVE-2020-3989LOW3.3VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability du...
CVE-2020-3988MEDIUM6.1VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ...
CVE-2020-3987MEDIUM6.1VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ...
CVE-2020-3986MEDIUM6.1VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ...
CVE-2020-3980MEDIUM6.7VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide ...
CVE-2020-7532HIGH7.8A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and pri...
CVE-2020-7531HIGH7.8A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allow...
CVE-2020-7530HIGH8.8A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows...
CVE-2020-7529MEDIUM5.5A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAP...
CVE-2020-7528HIGH7.8A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) w...
CVE-2020-4708MEDIUM5.3IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Contr...
CVE-2020-4409HIGH8.2IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbin...
CVE-2020-1748HIGH7.5A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityMan...
CVE-2020-10758HIGH7.5A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneous...
CVE-2020-25614CRITICAL9.8xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause...
CVE-2020-24891Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-24890MEDIUM5.5libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in...
CVE-2020-24889HIGH7.8A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp ...
CVE-2020-1710MEDIUM5.3The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a ...
CVE-2020-14382HIGH7.8A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, tha...
CVE-2020-10733HIGH7.3The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now