2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10049HIGH7.3A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts fo...
CVE-2020-7068LOW3.6In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar ext...
CVE-2020-15163HIGH8.2Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously do...
CVE-2020-13127HIGH8.8A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.04.1 allows remote authenticated attackers to...
CVE-2020-2044LOW3.3An information exposure through log file vulnerability where an administrator's password or other sensitive information ...
CVE-2020-2043LOW3.3An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log with...
CVE-2020-2042HIGH7.2A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt sy...
CVE-2020-2041HIGH7.5An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to ...
CVE-2020-2040CRITICAL9.8A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially...
CVE-2020-2039MEDIUM5.3An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user...
CVE-2020-2038HIGH7.2An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to exe...
CVE-2020-2037HIGH7.2An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to exe...
CVE-2020-2036HIGH8.8A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker ab...
CVE-2020-14292MEDIUM5.7In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connec...
CVE-2020-25213CRITICAL9.8The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra...
CVE-2020-25212HIGH7A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt me...
CVE-2020-25211MEDIUM6In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local...
CVE-2020-24566HIGH7.5In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment o...
CVE-2020-11986CRITICAL9.8To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This...
CVE-2020-24794MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.
CVE-2020-24200Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-24199CRITICAL9.8Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows a...
CVE-2020-24198MEDIUM6.1A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers t...
CVE-2020-24195CRITICAL9.1An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated ad...
CVE-2020-1749HIGH7.5A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tu...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now