2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4328MEDIUM6.3IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted S...
CVE-2020-8108HIGH8.8Improper Authentication vulnerability in Bitdefender Endpoint Security for Mac allows an unprivileged process to restart...
CVE-2020-14311MEDIUM6There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a sy...
CVE-2020-14310MEDIUM6There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max...
CVE-2020-5414MEDIUM5.7VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x vers...
CVE-2020-5413CRITICAL9.8Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo...
CVE-2020-5396HIGH8.8VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.1...
CVE-2020-15871HIGH8.8Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
CVE-2020-15870MEDIUM6.1Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
CVE-2020-15869MEDIUM5.4Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
CVE-2020-5384HIGH8.4Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerabil...
CVE-2020-15134HIGH8.7Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and ...
CVE-2020-15133HIGH8.7In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSo...
CVE-2020-15128MEDIUM6.3In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged...
CVE-2020-12081HIGH7.5An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal l...
CVE-2020-16136HIGH7.7In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the...
CVE-2020-9249MEDIUM6.5HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service vulnerability. A mod...
CVE-2020-9248MEDIUM6.7Huawei FusionComput 8.0.0 have an improper authorization vulnerability. A module does not verify some input correctly an...
CVE-2020-14520HIGH7.5The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information o...
CVE-2020-14337MEDIUM5.8A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw a...
CVE-2020-14334HIGH8.8A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials co...
CVE-2020-10731CRITICAL9.9A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SEL...
CVE-2020-3681CRITICAL9.8Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recov...
CVE-2020-3462MEDIUM6.3A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent...
CVE-2020-3461MEDIUM5.3A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now