2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4952 | HIGH | 8.8 | 2.0% | Jan 27, 2021 | IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-F... |
| CVE-2020-23356 | HIGH | 7.5 | 1.0% | Jan 27, 2021 | dmin/kernel/api/login.class.phpin in nibbleblog v3.7.1c allows type juggling for login bypass because == is used instead... |
| CVE-2020-23355 | HIGH | 7.5 | 1.0% | Jan 27, 2021 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in m... |
| CVE-2020-23352 | HIGH | 7.5 | 1.1% | Jan 27, 2021 | Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to by... |
| CVE-2020-23776 | HIGH | 7.5 | 0.8% | Jan 26, 2021 | A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vu... |
| CVE-2020-27295 | HIGH | 7.5 | 1.5% | Jan 26, 2021 | The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-serv... |
| CVE-2020-27274 | HIGH | 7.5 | 1.1% | Jan 26, 2021 | Some parsing functions in the affected product do not check the return value of malloc and the thread handling the messa... |
| CVE-2020-13582 | HIGH | 7.5 | 2.6% | Jan 26, 2021 | A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafte... |
| CVE-2020-9492 | HIGH | 8.8 | 4.4% | Jan 26, 2021 | In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO auth... |
| CVE-2020-8295 | HIGH | 7.5 | 1.8% | Jan 26, 2021 | A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password... |
| CVE-2020-36230 | HIGH | 7.5 | 12.3% | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in deco... |
| CVE-2020-36229 | HIGH | 7.5 | 4.3% | Jan 26, 2021 | A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad... |
| CVE-2020-36228 | HIGH | 7.5 | 83.4% | Jan 26, 2021 | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Ass... |
| CVE-2020-36227 | HIGH | 7.5 | 77.7% | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operat... |
| CVE-2020-36226 | HIGH | 7.5 | 4.3% | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAut... |
| CVE-2020-36225 | HIGH | 7.5 | 4.3% | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, ... |
| CVE-2020-36224 | HIGH | 7.5 | 4.3% | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo pr... |
| CVE-2020-36223 | HIGH | 7.5 | 4.3% | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, r... |
| CVE-2020-36222 | HIGH | 7.5 | 77.7% | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, ... |
| CVE-2020-36221 | HIGH | 7.5 | 84.2% | Jan 26, 2021 | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertio... |
| CVE-2020-36215 | HIGH | 7.5 | 1.4% | Jan 26, 2021 | An issue was discovered in the hashconsing crate before 1.1.0 for Rust. Because HConsed does not have bounds on its Send... |
| CVE-2020-36213 | HIGH | 7.5 | 1.4% | Jan 26, 2021 | An issue was discovered in the abi_stable crate before 0.9.1 for Rust. A retain call can create an invalid UTF-8 string,... |
| CVE-2020-36212 | HIGH | 7.5 | 1.4% | Jan 26, 2021 | An issue was discovered in the abi_stable crate before 0.9.1 for Rust. DrainFilter lacks soundness because of a double d... |
| CVE-2020-36211 | HIGH | 7 | 0.3% | Jan 26, 2021 | An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send ... |
| CVE-2020-36210 | HIGH | 7.8 | 0.4% | Jan 26, 2021 | An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized mem... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now