2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15168MEDIUM5.3node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means ...
CVE-2020-13920MEDIUM5.9Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi"...
CVE-2020-11998CRITICAL9.8A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnect...
CVE-2020-15024MEDIUM5.5An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562...
CVE-2020-9743MEDIUM6.1AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by...
CVE-2020-9742MEDIUM5.4AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability...
CVE-2020-9741MEDIUM5.4The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability ...
CVE-2020-9740MEDIUM5.4AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by...
CVE-2020-9738MEDIUM4.8AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by...
CVE-2020-9737MEDIUM4.8AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by...
CVE-2020-9736MEDIUM4.8AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by...
CVE-2020-9735MEDIUM4.8AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by...
CVE-2020-9734MEDIUM5.4The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability ...
CVE-2020-9733HIGH7.5An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high ...
CVE-2020-9732CRITICAL9The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability...
CVE-2020-4578MEDIUM5.4IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows...
CVE-2020-24582MEDIUM6.1Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user ...
CVE-2020-17408HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressClu...
CVE-2020-14198HIGH7.5Bitcoin Core 0.20.0 allows remote denial of service.
CVE-2020-10773MEDIUM4.4A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incor...
CVE-2020-8758CRITICAL9.8Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, ...
CVE-2020-6097HIGH7.5An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1...
CVE-2020-5780MEDIUM5.3Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to ve...
CVE-2020-25221HIGH7.8get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorr...
CVE-2020-24739MEDIUM6.5A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TO...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now