2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12102HIGH7.7In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionalit...
CVE-2020-10663HIGH7.5The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an...
CVE-2020-7451MEDIUM5.3In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE...
CVE-2020-12430MEDIUM6.5An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A...
CVE-2020-12429CRITICAL9.8Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and aut...
CVE-2020-11014HIGH8.6Electron-Cash-SLP before version 3.6.2 has a vulnerability. All token creators that use the "Mint Tool" feature of the E...
CVE-2020-9482MEDIUM6.5If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Regi...
CVE-2020-7644HIGH8.1fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modify...
CVE-2020-12243HIGH7.5In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial...
CVE-2020-10641HIGH7.5An unprotected logging route may allow an attacker to write endless log statements into the database without space limit...
CVE-2020-1745CRITICAL9.8A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in U...
CVE-2020-4329MEDIUM4.3IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenti...
CVE-2020-1774MEDIUM4.9When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore ...
CVE-2020-12078HIGH8.8An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/conf...
CVE-2020-10944MEDIUM5.4HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a ...
CVE-2020-10094MEDIUM5.4A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x befo...
CVE-2020-10093MEDIUM5.4A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
CVE-2020-12286MEDIUM4.3In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. Fo...
CVE-2020-5570MEDIUM5.4Cross-site scripting vulnerability in Sales Force Assistant version 11.2.48 and earlier allows remote authenticated atta...
CVE-2020-12284CRITICAL9.8cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MA...
CVE-2020-5568MEDIUM6.1Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 5.0.0 allows remote attackers to inject arbitrary web scrip...
CVE-2020-5567HIGH7.5Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in Applica...
CVE-2020-5566MEDIUM4.3Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the...
CVE-2020-5565MEDIUM4.3Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter...
CVE-2020-5564MEDIUM6.1Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to inject arbitrary web scri...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now