2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12063MEDIUM5.3A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homog...
CVE-2020-12135MEDIUM5.5bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular...
CVE-2020-12134CRITICAL9.8Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
CVE-2020-12132MEDIUM6.1Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request.
CVE-2020-12131MEDIUM6.1The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo).
CVE-2020-12130MEDIUM6.1The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.
CVE-2020-12129MEDIUM6.1The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.
CVE-2020-12128HIGH7.5DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
CVE-2020-12118HIGH8.2The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parame...
CVE-2020-11012HIGH7.5MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an ...
CVE-2020-5867HIGH8.1In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check...
CVE-2020-8798MEDIUM5.5httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the...
CVE-2020-5866MEDIUM5.5In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to ch...
CVE-2020-5865MEDIUM4.8In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over une...
CVE-2020-5864HIGH7.4In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS...
CVE-2020-8797MEDIUM6.7Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call ...
CVE-2020-7132MEDIUM5.4A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely...
CVE-2020-12113MEDIUM6.1BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
CVE-2020-12112HIGH7.5BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
CVE-2020-12105MEDIUM5.9OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers...
CVE-2020-7643MEDIUM5.3paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function c...
CVE-2020-4415CRITICAL9.8IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checki...
CVE-2020-4353MEDIUM4.6IBM MaaS360 6.82 could allow a user with pysical access to the device to crash the application which may enable the user...
CVE-2020-4311HIGH7IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially...
CVE-2020-4202HIGH8.8IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the serv...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now