2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5610HIGH7.8Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service...
CVE-2020-16143HIGH7.8The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current...
CVE-2020-16135MEDIUM5.9libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
CVE-2020-14308MEDIUM6.4In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested...
CVE-2020-5763HIGH8.8Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated rem...
CVE-2020-5762HIGH7.5Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-...
CVE-2020-5761HIGH7.5Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in ...
CVE-2020-5760HIGH7.8Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Una...
CVE-2020-14316CRITICAL9.9A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's...
CVE-2020-16118HIGH7.5In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and...
CVE-2020-16117MEDIUM5.9In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer derefere...
CVE-2020-15707MEDIUM6.4Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRU...
CVE-2020-15706MEDIUM6.4GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be ...
CVE-2020-15705MEDIUM6.4GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This on...
CVE-2020-15588CRITICAL9.8An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled serve...
CVE-2020-15125HIGH7.7In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request obj...
CVE-2020-15099HIGH8.1In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4...
CVE-2020-15098HIGH8.8In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4...
CVE-2020-15086CRITICAL9.8In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered ...
CVE-2020-11934MEDIUM5.9It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the syste...
CVE-2020-11933MEDIUM6.8cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, ...
CVE-2020-13699HIGH8.8TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could ...
CVE-2020-8553MEDIUM5.9The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and t...
CVE-2020-16095MEDIUM6.1The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.
CVE-2020-4645MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows user...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now