2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8226MEDIUM5.8A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
CVE-2020-8212CRITICAL9.8Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix Xe...
CVE-2020-8211CRITICAL9.8Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix ...
CVE-2020-8210HIGH7.5Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6...
CVE-2020-8209HIGH7.5Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe...
CVE-2020-8208MEDIUM6.1Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix ...
CVE-2020-13122HIGH8.8The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, i...
CVE-2020-9242HIGH8.8FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain paramete...
CVE-2020-9103MEDIUM4.6HUAWEI Mate 20 smartphones with 9.0.0.205(C00E205R2P1) have a logic error vulnerability. In a special scenario, the syst...
CVE-2020-7703CRITICAL9.8All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.
CVE-2020-7702CRITICAL9.8All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.
CVE-2020-12606CRITICAL9.8An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webs...
CVE-2020-4686HIGH8.1IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform ...
CVE-2020-13941HIGH8.8Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handl...
CVE-2020-24361CRITICAL9.8SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
CVE-2020-17475HIGH7.5Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to...
CVE-2020-17474CRITICAL9.8A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to...
CVE-2020-17473MEDIUM5.9Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker ...
CVE-2020-17464Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-14353Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-18270. Reason: This candidate is a duplicate of ...
CVE-2020-0255Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10751. Reason: This candidate is a duplicate of ...
CVE-2020-15694HIGH7.5In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.ge...
CVE-2020-15693MEDIUM6.5In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is poss...
CVE-2020-15692CRITICAL9.8In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument ca...
CVE-2020-9767HIGH7.8A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now