2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-24393MEDIUM5.9TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allo...
CVE-2020-24392MEDIUM5.9In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attac...
CVE-2020-12668MEDIUM6.5Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context....
CVE-2020-35499MEDIUM6.7A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in ne...
CVE-2020-12374MEDIUM6.7Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2...
CVE-2020-36248MEDIUM4.6The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a bac...
CVE-2020-36252MEDIUM5.7ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version o...
CVE-2020-36251MEDIUM4.3ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove...
CVE-2020-36250MEDIUM4.6In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system ...
CVE-2020-10254MEDIUM5.9An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by ...
CVE-2020-35776MEDIUM6.5A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remo...
CVE-2020-35592MEDIUM5.4Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitra...
CVE-2020-35591MEDIUM5.4Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the us...
CVE-2020-28463MEDIUM6.5All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce ...
CVE-2020-4933MEDIUM5.4IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allo...
CVE-2020-35577MEDIUM6.5In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to ...
CVE-2020-25605MEDIUM5.9Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain acces...
CVE-2020-12365MEDIUM5.5Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5...
CVE-2020-8765MEDIUM6.7Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potenti...
CVE-2020-8701MEDIUM6.7Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021 may allow a privileged ...
CVE-2020-24505MEDIUM4.4Insufficient input validation in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 7.3 may...
CVE-2020-24504MEDIUM5.5Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allo...
CVE-2020-24503MEDIUM5.5Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an a...
CVE-2020-24502MEDIUM5.5Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before versi...
CVE-2020-24501MEDIUM6.5Buffer overflow in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow an unauthentica...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now