2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14061HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-13656CRITICAL9.8In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an...
CVE-2020-11839MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to ...
CVE-2020-10752HIGH7.5A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into t...
CVE-2020-11980MEDIUM6.3In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "...
CVE-2020-4050LOW3.1In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fi...
CVE-2020-4049LOW2.4In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that coul...
CVE-2020-4048MEDIUM5.7In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external...
CVE-2020-4047MEDIUM6.8In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScr...
CVE-2020-4046MEDIUM5.4In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in ...
CVE-2020-14004HIGH7.8An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd servi...
CVE-2020-9651MEDIUM6.1Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (reflected) vulnerability. Successful expl...
CVE-2020-9648MEDIUM6.1Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation cou...
CVE-2020-9647MEDIUM6.1Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (dom-based) vulnerability. Successful expl...
CVE-2020-9645HIGH7.5Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Success...
CVE-2020-9644MEDIUM5.4Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (stored) vulnerability. Successful exploit...
CVE-2020-9643HIGH7.5Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful ex...
CVE-2020-9636HIGH8.8Adobe Framemaker versions 2019.0.5 and below have a memory corruption vulnerability. Successful exploitation could lead ...
CVE-2020-9635HIGH8.8Adobe Framemaker versions 2019.0.5 and below have an out-of-bounds write vulnerability. Successful exploitation could le...
CVE-2020-9634HIGH8.8Adobe Framemaker versions 2019.0.5 and below have an out-of-bounds write vulnerability. Successful exploitation could le...
CVE-2020-9633CRITICAL9.8Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, ...
CVE-2020-10732MEDIUM4.4A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local...
CVE-2020-4251MEDIUM5.4IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2020-3930LOW3.3GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read the...
CVE-2020-3929MEDIUM5.9GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may c...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now