2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-4952HIGH8.8IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-F...
CVE-2020-23356HIGH7.5dmin/kernel/api/login.class.phpin in nibbleblog v3.7.1c allows type juggling for login bypass because == is used instead...
CVE-2020-23355HIGH7.5** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in m...
CVE-2020-23352HIGH7.5Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to by...
CVE-2020-23776HIGH7.5A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vu...
CVE-2020-27295HIGH7.5The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-serv...
CVE-2020-27274HIGH7.5Some parsing functions in the affected product do not check the return value of malloc and the thread handling the messa...
CVE-2020-13582HIGH7.5A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafte...
CVE-2020-9492HIGH8.8In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO auth...
CVE-2020-8295HIGH7.5A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password...
CVE-2020-36230HIGH7.5A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in deco...
CVE-2020-36229HIGH7.5A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad...
CVE-2020-36228HIGH7.5An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Ass...
CVE-2020-36227HIGH7.5A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operat...
CVE-2020-36226HIGH7.5A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAut...
CVE-2020-36225HIGH7.5A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, ...
CVE-2020-36224HIGH7.5A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo pr...
CVE-2020-36223HIGH7.5A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, r...
CVE-2020-36222HIGH7.5A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, ...
CVE-2020-36221HIGH7.5An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertio...
CVE-2020-36215HIGH7.5An issue was discovered in the hashconsing crate before 1.1.0 for Rust. Because HConsed does not have bounds on its Send...
CVE-2020-36213HIGH7.5An issue was discovered in the abi_stable crate before 0.9.1 for Rust. A retain call can create an invalid UTF-8 string,...
CVE-2020-36212HIGH7.5An issue was discovered in the abi_stable crate before 0.9.1 for Rust. DrainFilter lacks soundness because of a double d...
CVE-2020-36211HIGH7An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send ...
CVE-2020-36210HIGH7.8An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized mem...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now