2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24381HIGH7.5GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessm...
CVE-2020-5385HIGH7.8Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escala...
CVE-2020-24032CRITICAL9.8tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharac...
CVE-2020-23934HIGH8.8An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php ...
CVE-2020-15926MEDIUM6.1Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct ...
CVE-2020-15865CRITICAL9.8A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode ...
CVE-2020-9415MEDIUM6.5The TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtual...
CVE-2020-23933Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-7019MEDIUM6.5In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Le...
CVE-2020-7018HIGH8.8Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is give...
CVE-2020-24212Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. This candidate was erroneously published without a public reference c...
CVE-2020-23938Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. This candidate was erroneously published without a public reference c...
CVE-2020-14936CRITICAL9.8Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. Functions parsing the OIDs in SNMP re...
CVE-2020-14935CRITICAL9.8Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function....
CVE-2020-14934CRITICAL9.8Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. The function parsing the received SNM...
CVE-2020-14937CRITICAL9.1Memory access out of buffer boundaries issues was discovered in Contiki-NG 4.4 through 4.5, in the SNMP BER encoder/deco...
CVE-2020-7708CRITICAL9.8The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via ...
CVE-2020-7707CRITICAL9.8The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
CVE-2020-14333MEDIUM6.1A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable par...
CVE-2020-7706CRITICAL9.8The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by...
CVE-2020-15152CRITICAL9.1ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv...
CVE-2020-13933HIGH7.5Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
CVE-2020-13183MEDIUM6.1Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over ...
CVE-2020-12480MEDIUM6.5In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types...
CVE-2020-1597HIGH7.5A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now