2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9288MEDIUM5.4An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a ...
CVE-2020-6644HIGH8.1An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpi...
CVE-2020-4070MEDIUM5.4In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A...
CVE-2020-4068CRITICAL9.8In APNSwift 1.0.0, calling APNSwiftSigner.sign(digest:) is likely to result in a heap buffer overflow. This has been fix...
CVE-2020-4066HIGH7.2In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are un...
CVE-2020-4062CRITICAL9In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the ...
CVE-2020-4060MEDIUM5In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug i...
CVE-2020-13887HIGH8.8documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to...
CVE-2020-13279HIGH8.6Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system
CVE-2020-13888MEDIUM5.4Kordil EDMS through 2.2.60rc3 allows stored XSS in users_edit.php, users_management_edit.php, and user_management.php.
CVE-2020-8933HIGH7.8A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on...
CVE-2020-8907HIGH7.8A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on...
CVE-2020-8903HIGH7.8A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on...
CVE-2020-14461HIGH8.6Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
CVE-2020-14204HIGH8.2In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local f...
CVE-2020-14203HIGH8.8WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users ...
CVE-2020-14202MEDIUM6.1WebFOCUS Business Intelligence 8.0 (SP6) was prone to XSS via arbitrary URL parameters.
CVE-2020-14969HIGH7.5app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the att...
CVE-2020-14968CRITICAL9.8An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does...
CVE-2020-14967CRITICAL9.8An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation...
CVE-2020-14966HIGH7.5An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signature...
CVE-2020-8102HIGH8.8Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an ex...
CVE-2020-7262MEDIUM5.5Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view...
CVE-2020-3676HIGH7.8Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdr...
CVE-2020-3665HIGH7.8A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firm...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now