2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14304MEDIUM4.4A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of th...
CVE-2020-11977HIGH7.2In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow ...
CVE-2020-9416MEDIUM5.4The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS...
CVE-2020-15172HIGH8.8The Act module for Red Discord Bot before commit 6b9f3b86 is vulnerable to Remote Code Execution. With this exploit, Dis...
CVE-2020-15148CRITICAL10Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize(...
CVE-2020-14362HIGH7.8A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may...
CVE-2020-14361HIGH7.8A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may...
CVE-2020-14346HIGH7.8A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in th...
CVE-2020-14331MEDIUM6.6A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker att...
CVE-2020-10759MEDIUM6A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware...
CVE-2020-25071MEDIUM5.4Nifty Project Management Web Application 2020-08-26 allows XSS, via Add Task, that is rendered upon a Project Home visit...
CVE-2020-15179CRITICAL9The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using <script> tag insid...
CVE-2020-15178CRITICAL9.3In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript...
CVE-2020-8346MEDIUM5.5A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation...
CVE-2020-8342HIGH7A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalati...
CVE-2020-8340MEDIUM6.1A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Managem...
CVE-2020-8339MEDIUM6.1A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Mod...
CVE-2020-4711MEDIUM6.5IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An ...
CVE-2020-4703HIGH8IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload a...
CVE-2020-4530MEDIUM5.4IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site s...
CVE-2020-4526MEDIUM4.3IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to...
CVE-2020-4521HIGH8.8IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the...
CVE-2020-4344LOW3.3IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by an...
CVE-2020-23512CRITICAL9.8VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the ...
CVE-2020-23451HIGH8.8Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" func...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now