2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2002HIGH8.1An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Al...
CVE-2020-2001CRITICAL9.8An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that ...
CVE-2020-1998HIGH8.8An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of t...
CVE-2020-1997MEDIUM6.1An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to spec...
CVE-2020-1996MEDIUM5.3A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthentica...
CVE-2020-1995MEDIUM4.9A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a re...
CVE-2020-1994MEDIUM4.4A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbi...
CVE-2020-1993MEDIUM5.4The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which al...
CVE-2020-1714HIGH8.8A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without typ...
CVE-2020-11073HIGH7.8In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could...
CVE-2020-11070MEDIUM5.4The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invali...
CVE-2020-12832CRITICAL9.8WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files be...
CVE-2020-12831MEDIUM5.3An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, th...
CVE-2020-5407HIGH8.8Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during...
CVE-2020-9502CRITICAL9.8Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user...
CVE-2020-9501MEDIUM5.5Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authent...
CVE-2020-7455MEDIUM5.5In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3...
CVE-2020-7454CRITICAL9.8In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3...
CVE-2020-5838MEDIUM4.8Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of is...
CVE-2020-8020MEDIUM6.1A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attacker...
CVE-2020-12763CRITICAL9.8TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow i...
CVE-2020-12427HIGH8.8The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF,...
CVE-2020-4312MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitiv...
CVE-2020-12742MEDIUM6.1The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols.
CVE-2020-12700MEDIUM4.3The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now