2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13176MEDIUM6.1The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to ...
CVE-2020-13175HIGH7.5The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to ...
CVE-2020-13174MEDIUM6.1The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HT...
CVE-2020-17466CRITICAL9.8Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redir...
CVE-2020-17448HIGH7.8Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechan...
CVE-2020-17368CRITICAL9.8Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may ...
CVE-2020-17367HIGH7.8Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to comm...
CVE-2020-16092LOW3.8In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e an...
CVE-2020-15597MEDIUM5.4SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment fi...
CVE-2020-13124HIGH8.8SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an a...
CVE-2020-11552CRITICAL9.8An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not ...
CVE-2020-14324CRITICAL9.1A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS...
CVE-2020-14313MEDIUM4.3An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker...
CVE-2020-14296HIGH7.1Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible T...
CVE-2020-10780MEDIUM6.3Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as ...
CVE-2020-14325CRITICAL9.1Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious at...
CVE-2020-10783HIGH8.3Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group ...
CVE-2020-10779MEDIUM6.5Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypas...
CVE-2020-10778MEDIUM6In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled a...
CVE-2020-10777MEDIUM5.4A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this...
CVE-2020-4486HIGH8.1IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw af...
CVE-2020-4485MEDIUM6.5IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an at...
CVE-2020-9079HIGH8.8FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protectio...
CVE-2020-16278MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could...
CVE-2020-16277HIGH8.8An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, au...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now