2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-17366HIGH7.4An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended acce...
CVE-2020-7298HIGH8.4Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real tim...
CVE-2020-15132MEDIUM5.3In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu ...
CVE-2020-15127HIGH7.5In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, ...
CVE-2020-13404HIGH8.8The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
CVE-2020-16254MEDIUM6.1The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
CVE-2020-15113HIGH7.1In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory pa...
CVE-2020-15112MEDIUM6.5In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in t...
CVE-2020-15106MEDIUM6.5In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is st...
CVE-2020-16192MEDIUM6.1LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parame...
CVE-2020-17364MEDIUM6.1USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
CVE-2020-8607MEDIUM6.7An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific ro...
CVE-2020-5609CRITICAL9.8Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, C...
CVE-2020-5608CRITICAL9.8CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, B...
CVE-2020-4481HIGH8.2IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE...
CVE-2020-4243LOW3.7IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensit...
CVE-2020-17353CRITICAL9.8scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restri...
CVE-2020-16253HIGH8.1The PgHero gem through 2.6.0 for Ruby allows CSRF.
CVE-2020-16252MEDIUM4.3The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.
CVE-2020-14347MEDIUM5.5A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X...
CVE-2020-14344MEDIUM6.7An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in li...
CVE-2020-13921CRITICAL9.8**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the w...
CVE-2020-13819MEDIUM6.1Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
CVE-2020-13151CRITICAL9.8Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)...
CVE-2020-15109MEDIUM5.3In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering addre...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now