2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12104HIGH8.8The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via...
CVE-2020-11737MEDIUM6.1A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-M...
CVE-2020-12659MEDIUM6.7An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write ...
CVE-2020-12657HIGH7.8An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bf...
CVE-2020-12656MEDIUM5.5gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through...
CVE-2020-12655MEDIUM5.5An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may...
CVE-2020-12653HIGH7.8An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marv...
CVE-2020-12654HIGH7.1An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wm...
CVE-2020-12652MEDIUM4.1The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to h...
CVE-2020-12649HIGH7.5Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths.
CVE-2020-10717MEDIUM6.5A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version...
CVE-2020-10700MEDIUM5.3A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with th...
CVE-2020-10686MEDIUM4.7A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user re...
CVE-2020-8896MEDIUM5.9A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 all...
CVE-2020-5343HIGH7.8Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecu...
CVE-2020-5337MEDIUM6.1RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attack...
CVE-2020-5336MEDIUM6.1RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could...
CVE-2020-5335HIGH8.8RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthentic...
CVE-2020-5334MEDIUM6.1RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulner...
CVE-2020-5333MEDIUM4.3RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote ...
CVE-2020-5332HIGH7.2RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious us...
CVE-2020-5331MEDIUM5.5RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session informatio...
CVE-2020-10622HIGH7.8LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorize...
CVE-2020-10618MEDIUM5.5LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unau...
CVE-2020-1732MEDIUM4.2A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now