2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12642HIGH7.5An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resulta...
CVE-2020-12109HIGH8.8Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 ...
CVE-2020-12641CRITICAL9.8rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in...
CVE-2020-12640CRITICAL9.8Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plu...
CVE-2020-12111HIGH8.8Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
CVE-2020-10933MEDIUM5.3An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_...
CVE-2020-8792MEDIUM5.3The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. I...
CVE-2020-8791MEDIUM6.5The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit AP...
CVE-2020-8790CRITICAL9.8The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combi...
CVE-2020-4209MEDIUM5.4IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An ...
CVE-2020-12639MEDIUM6.1phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
CVE-2020-12475MEDIUM5.5TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.p...
CVE-2020-12110CRITICAL9.8Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304,...
CVE-2020-11671HIGH8.1Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid...
CVE-2020-11462HIGH7.5An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interf...
CVE-2020-11443HIGH8.1The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoo...
CVE-2020-10876HIGH7.5The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its tim...
CVE-2020-10187HIGH7.5Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve ...
CVE-2020-1961CRITICAL9.8Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1...
CVE-2020-1959CRITICAL9.8A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary ...
CVE-2020-12629MEDIUM5.4include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
CVE-2020-11842HIGH7.5Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier...
CVE-2020-8018HIGH7.8A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of ...
CVE-2020-12114MEDIUM4.7A pivot_root race condition in fs/namespace.c in the Linux kernel 4.4.x before 4.4.221, 4.9.x before 4.9.221, 4.14.x bef...
CVE-2020-1631CRITICAL9.8A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now