2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6458HIGH8.8Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially ...
CVE-2020-6457CRITICAL9.6Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially per...
CVE-2020-13252HIGH8.8Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRD...
CVE-2020-12647HIGH8.8Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences...
CVE-2020-5365HIGH7.5Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, re...
CVE-2020-5364HIGH7.5Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by def...
CVE-2020-9484HIGH7When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a)...
CVE-2020-13249HIGH8.8libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet rece...
CVE-2020-13241HIGH7.8Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not veri...
CVE-2020-13246HIGH7.5An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a reposi...
CVE-2020-11078MEDIUM6.8In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could cha...
CVE-2020-13240MEDIUM5.4The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded ...
CVE-2020-13239MEDIUM5.4The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is ...
CVE-2020-5753MEDIUM5.3Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's S...
CVE-2020-3956HIGH8.8VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4...
CVE-2020-1955CRITICAL9.8CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server...
CVE-2020-13231MEDIUM6.5In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
CVE-2020-13230MEDIUM4.3In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account...
CVE-2020-11716CRITICAL9.8Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the...
CVE-2020-10726MEDIUM4.4A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-us...
CVE-2020-10725HIGH7.7A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhos...
CVE-2020-9410HIGH8.8The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for Act...
CVE-2020-9409CRITICAL9.8The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS ...
CVE-2020-4461MEDIUM6.5IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token ...
CVE-2020-13152MEDIUM5.5A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will tri...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now