2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13432HIGH7.5rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to ...
CVE-2020-10754MEDIUM4.3It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-p...
CVE-2020-8954MEDIUM5.4OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manip...
CVE-2020-5304HIGH7.5The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a...
CVE-2020-13696MEDIUM4.4An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient...
CVE-2020-13625HIGH7.5PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote charac...
CVE-2020-12800CRITICAL9.8The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa...
CVE-2020-12695HIGH7.5The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription r...
CVE-2020-12049MEDIUM5.5An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file d...
CVE-2020-9042HIGH8.8In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has us...
CVE-2020-9041HIGH7.5In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text ...
CVE-2020-9040HIGH7.5Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intende...
CVE-2020-1775MEDIUM4.3BCC recipients in mails sent from OTRS are visible in article detail on external interface. This issue affects OTRS: 8.0...
CVE-2020-13866HIGH7.8WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges...
CVE-2020-12803MEDIUM6.5ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be subm...
CVE-2020-12802MEDIUM5.3LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote ...
CVE-2020-9099CRITICAL9.8Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6...
CVE-2020-8180CRITICAL9.9A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk co...
CVE-2020-8172HIGH7.4TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
CVE-2020-7676MEDIUM5.4angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code in...
CVE-2020-6110HIGH8.8An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages incl...
CVE-2020-6109CRITICAL9.8An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including anima...
CVE-2020-4529HIGH7.4IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authe...
CVE-2020-12773HIGH8.8A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows at...
CVE-2020-13912HIGH7.3SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, b...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now