2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11018MEDIUM6.5In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients...
CVE-2020-12675HIGH8.8The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks...
CVE-2020-11017MEDIUM6.5In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condi...
CVE-2020-4490MEDIUM6.1IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote atta...
CVE-2020-4352HIGH7IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IB...
CVE-2020-4306MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2020-5573MEDIUM4.6Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in ...
CVE-2020-5572MEDIUM4.6Android App 'Mailwise for Android' 1.0.0 to 1.0.1 allows an attacker to obtain credential information registered in the ...
CVE-2020-13693CRITICAL9.8An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi...
CVE-2020-13173HIGH7.8Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent fo...
CVE-2020-11082MEDIUM6.1In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with...
CVE-2020-5357MEDIUM6Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File O...
CVE-2020-13660MEDIUM4.8CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
CVE-2020-13245MEDIUM5.9Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1....
CVE-2020-11079CRITICAL9.8node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote...
CVE-2020-8330HIGH7.5A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN tha...
CVE-2020-8329HIGH7.5A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN tha...
CVE-2020-4248LOW2.7IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information wh...
CVE-2020-4419MEDIUM5.4IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2020-4249MEDIUM6.5IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticat...
CVE-2020-4246HIGH7.1IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack w...
CVE-2020-4245HIGH7.5IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by defa...
CVE-2020-4244MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information...
CVE-2020-4233MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, c...
CVE-2020-4232HIGH7.5IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid log...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now