2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9296CRITICAL9.8Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violatio...
CVE-2020-8544MEDIUM6.5OX App Suite through 7.10.3 allows SSRF.
CVE-2020-8543HIGH7.5OX App Suite through 7.10.3 has Improper Input Validation.
CVE-2020-8542MEDIUM5.4OX App Suite through 7.10.3 allows XSS.
CVE-2020-8541MEDIUM6.5OX App Suite through 7.10.3 allows XXE attacks.
CVE-2020-4320MEDIUM6.5IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients base...
CVE-2020-4310HIGH7.5IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to a...
CVE-2020-12494MEDIUM5.3Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implement...
CVE-2020-11841MEDIUM4.3Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions ...
CVE-2020-11840MEDIUM4.3Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions ...
CVE-2020-11838MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2....
CVE-2020-0235CRITICAL9.8In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size...
CVE-2020-0234HIGH7.8In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. T...
CVE-2020-0232CRITICAL9.8Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work wi...
CVE-2020-0223CRITICAL9.8This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Androi...
CVE-2020-13431HIGH7.8I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions o...
CVE-2020-4051MEDIUM5.4In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to...
CVE-2020-5358HIGH7.8Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escala...
CVE-2020-14163HIGH7.5An issue was discovered in ecma/operations/ecma-container-object.c in JerryScript 2.2.0. Operations with key/value pairs...
CVE-2020-5755HIGH7.8Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against ren...
CVE-2020-5754CRITICAL9.1Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability ov...
CVE-2020-5742HIGH8.8Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin applicatio...
CVE-2020-12019CRITICAL9.8WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to re...
CVE-2020-12005HIGH7.5FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio...
CVE-2020-12003HIGH7.5FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now