2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5563MEDIUM5.3Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in the aff...
CVE-2020-5562MEDIUM4.9Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an admini...
CVE-2020-9481HIGH7.5Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
CVE-2020-7640CRITICAL9.8pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be con...
CVE-2020-7609CRITICAL9.8node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fr...
CVE-2020-7067HIGH7.5In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (un...
CVE-2020-1762HIGH8.6An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version ...
CVE-2020-1722MEDIUM5.3A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to...
CVE-2020-11869LOW3.3An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs ...
CVE-2020-9294CRITICAL9.8An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an...
CVE-2020-1952CRITICAL9.8An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed ...
CVE-2020-12279CRITICAL9.8An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that...
CVE-2020-12278CRITICAL9.8An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exi...
CVE-2020-11941HIGH8.8An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
CVE-2020-9488LOW3.7Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connectio...
CVE-2020-9068CRITICAL9.8Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200...
CVE-2020-1880MEDIUM5.5Huawei smartphone Lion-AL00C with versions earlier than 10.0.0.205(C00E202R7P2) have a denial of service vulnerability. ...
CVE-2020-9072MEDIUM6.7Huawei OSD product with versions earlier than OSD_uwp_9.0.32.0 have a local privilege escalation vulnerability. An authe...
CVE-2020-7135HIGH7.8A potential security vulnerability has been identified in the disk drive firmware installers named Supplemental Update /...
CVE-2020-1845MEDIUM6.7Huawei PCManager product with versions earlier than 10.0.5.53 have a local privilege escalation vulnerability. An authen...
CVE-2020-1807LOW3.5HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.188(C00E74R3P8) have an improper authorization vulnerabilit...
CVE-2020-1806HIGH7.1Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities....
CVE-2020-1805HIGH7.1Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities....
CVE-2020-1804HIGH7.1Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities....
CVE-2020-12266HIGH7.5An issue was discovered where there are multiple externally accessible pages that do not require any sort of authenticat...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now