2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3186MEDIUM5.3A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow...
CVE-2020-3179HIGH7.5A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defens...
CVE-2020-3178MEDIUM6.1Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance ...
CVE-2020-3125CRITICAL9.8A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow a...
CVE-2020-7921MEDIUM5.3Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem perm...
CVE-2020-12108MEDIUM6.5/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
CVE-2020-6861MEDIUM5.5A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attac...
CVE-2020-4446MEDIUM4.3IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote a...
CVE-2020-4421MEDIUM5.4IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spo...
CVE-2020-4384MEDIUM5.4IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2020-10704HIGH7.5A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain request...
CVE-2020-10693MEDIUM5.3A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invali...
CVE-2020-7806CRITICAL9.8Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supporte...
CVE-2020-6094HIGH8.8An exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Acc...
CVE-2020-6082HIGH8.8An exploitable out-of-bounds write vulnerability exists in the ico_read function of the igcore19d.dll library of Accusof...
CVE-2020-6076HIGH8.8An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll ICO icoread parser of the Accusoft ImageGea...
CVE-2020-6075HIGH8.8An exploitable out-of-bounds write vulnerability exists in the store_data_buffer function of the igcore19d.dll library o...
CVE-2020-4092MEDIUM5.3"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clea...
CVE-2020-2189HIGH8.8Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of ar...
CVE-2020-2188MEDIUM4.3A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Ov...
CVE-2020-2187MEDIUM5.6Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostn...
CVE-2020-2186MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision...
CVE-2020-2185MEDIUM5.6Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the...
CVE-2020-2184MEDIUM4.3A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipul...
CVE-2020-2183MEDIUM6.5Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifact...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now