2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-19642MEDIUM6.2An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitra...
CVE-2020-7464MEDIUM5.3In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and ...
CVE-2020-7463MEDIUM5.5In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 1...
CVE-2020-7462MEDIUM5.5In 11.4-PRERELEASE before r360733 and 11.3-RELEASE before p13, improper mbuf handling in the kernel causes a use-after-f...
CVE-2020-25580MEDIUM5.3In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a r...
CVE-2020-25579MEDIUM5.3In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 1...
CVE-2020-25578MEDIUM5.3In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 1...
CVE-2020-35518MEDIUM5.3When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or n...
CVE-2020-35508MEDIUM4.5A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/...
CVE-2020-27829MEDIUM5.5A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7....
CVE-2020-35856MEDIUM4.8SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
CVE-2020-19626MEDIUM5.4Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or H...
CVE-2020-25840MEDIUM6.1Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The ...
CVE-2020-23517MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers...
CVE-2020-15809MEDIUM6.5spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversa...
CVE-2020-12483MEDIUM6.1The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps...
CVE-2020-9212MEDIUM6.5There is a vulnerability in some version of USG9500 that the device improperly handles the information when a user logs ...
CVE-2020-9206MEDIUM6.7The eUDC660 product has a resource management vulnerability. An attacker with high privilege needs to perform specific o...
CVE-2020-4882MEDIUM6.1IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from u...
CVE-2020-27171MEDIUM6An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resulta...
CVE-2020-27170MEDIUM4.7An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds spec...
CVE-2020-4635MEDIUM5.3IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames.
CVE-2020-6578MEDIUM6.1Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_...
CVE-2020-36144MEDIUM5.3Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escapi...
CVE-2020-17457MEDIUM5.4Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FI...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now