2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13143MEDIUM6.5gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup wit...
CVE-2020-8034MEDIUM6.1Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected C...
CVE-2020-6093MEDIUM5.5An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A sp...
CVE-2020-6092HIGH7.8An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially c...
CVE-2020-6074HIGH8.8An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF do...
CVE-2020-13136HIGH7.5D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer.
CVE-2020-13135MEDIUM6.5D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstra...
CVE-2020-11551HIGH8.8An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel...
CVE-2020-11550MEDIUM6.5An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel...
CVE-2020-11549HIGH8.8An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel...
CVE-2020-8035MEDIUM6.1The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripti...
CVE-2020-12801MEDIUM5.3If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffic...
CVE-2020-12256MEDIUM5.4rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can ...
CVE-2020-12255HIGH8.8rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor...
CVE-2020-10967MEDIUM5.3In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail wi...
CVE-2020-9524MEDIUM5.4Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions pri...
CVE-2020-12258CRITICAL9.1rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application...
CVE-2020-12257HIGH8.8rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such...
CVE-2020-10958MEDIUM5.3In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-log...
CVE-2020-10957HIGH7.5In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dere...
CVE-2020-12259MEDIUM5.4rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can...
CVE-2020-13129HIGH7.2An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms...
CVE-2020-12860MEDIUM5.3COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can h...
CVE-2020-12859MEDIUM5.3Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify ...
CVE-2020-12858HIGH7.5Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now