2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10134MEDIUM6.3Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairi...
CVE-2020-10030HIGH8.8An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privile...
CVE-2020-8021MEDIUM5.3a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package...
CVE-2020-1695HIGH7.5A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Fin...
CVE-2020-11845MEDIUM6.1Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9....
CVE-2020-8617MEDIUM5.9Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the...
CVE-2020-8616HIGH8.6A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when p...
CVE-2020-6956MEDIUM6.1PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp.
CVE-2020-4412MEDIUM5.3The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of...
CVE-2020-4411HIGH7.1The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of...
CVE-2020-4298MEDIUM5.4IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2020-4286MEDIUM6.5IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an ...
CVE-2020-12663HIGH7.5Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
CVE-2020-12662HIGH7.5Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered b...
CVE-2020-12244HIGH7.5An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN respo...
CVE-2020-8434CRITICAL9.8Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch ...
CVE-2020-12667HIGH7.5Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka...
CVE-2020-1897CRITICAL9.8A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invok...
CVE-2020-13154MEDIUM6.5Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Pro...
CVE-2020-13153MEDIUM6.1app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
CVE-2020-13094MEDIUM5.4Dolibarr before 11.0.4 allows XSS.
CVE-2020-13149HIGH7.8Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Mic...
CVE-2020-13146HIGH8.8Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a ...
CVE-2020-13145MEDIUM5.4Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can ...
CVE-2020-13144HIGH8.8Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now