2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-26822CRITICAL10SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o...
CVE-2020-26821CRITICAL10SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o...
CVE-2020-25074CRITICAL9.8The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request...
CVE-2020-7766CRITICAL9.8This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr...
CVE-2020-13927CRITICAL9.8The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th...
CVE-2020-24384CRITICAL9.8A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution ...
CVE-2020-0452CRITICAL9.8In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could ...
CVE-2020-0447CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-0446CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-0445CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-28371CRITICAL9.8An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. The FileOutputStream.write() method in FileOutputStr...
CVE-2020-26168CRITICAL9.8The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x ...
CVE-2020-14189CRITICAL9.8The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to ex...
CVE-2020-14188CRITICAL9.8The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to...
CVE-2020-26542CRITICAL9.8An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDA...
CVE-2020-23138CRITICAL9.8An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can up...
CVE-2020-15297CRITICAL9.1Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tool...
CVE-2020-24407CRITICAL9.1Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result i...
CVE-2020-28347CRITICAL9.8tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl...
CVE-2020-28340CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypa...
CVE-2020-3284CRITICAL9.8A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could a...
CVE-2020-26214CRITICAL9.8In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when A...
CVE-2020-25172CRITICAL9.8A relative path traversal attack in the B. Braun OnlineSuite Version AP 3.0 and earlier allows unauthenticated attackers...
CVE-2020-26892CRITICAL9.8The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are han...
CVE-2020-25592CRITICAL9.8In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authent...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now