2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11416MEDIUM5.4JetBrains Space through 2020-04-22 allows stored XSS in Chats.
CVE-2020-12059HIGH7.5An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by ...
CVE-2020-12051HIGH7.5The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account infor...
CVE-2020-5301LOW3.1SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSA...
CVE-2020-11008HIGH7.5Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host cont...
CVE-2020-10569CRITICAL9.8SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additiona...
CVE-2020-8895HIGH7.8Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attac...
CVE-2020-5268HIGH7.3In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerabilit...
CVE-2020-1757HIGH8.1A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x ...
CVE-2020-1699HIGH7.5A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph...
CVE-2020-11891MEDIUM5.3An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow th...
CVE-2020-11890MEDIUM5.3An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to ...
CVE-2020-11889MEDIUM5.3An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow th...
CVE-2020-10787HIGH8.8An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the...
CVE-2020-10786HIGH8.8A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary co...
CVE-2020-8842Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-1967HIGH7.5Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due...
CVE-2020-11828HIGH7.5In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger su...
CVE-2020-8099MEDIUM6.2A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to su...
CVE-2020-11968HIGH7.5In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. N...
CVE-2020-11967CRITICAL9.8In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of ...
CVE-2020-11966CRITICAL9.8In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root p...
CVE-2020-11965CRITICAL9.8In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access vi...
CVE-2020-11964HIGH7.5In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the roo...
CVE-2020-11963CRITICAL9.8IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now