2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11464MEDIUM4.3An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privil...
CVE-2020-11463HIGH7.5An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user'...
CVE-2020-10948CRITICAL9.8Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution v...
CVE-2020-10598MEDIUM6.1In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment es...
CVE-2020-5290MEDIUM6.5In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` has...
CVE-2020-1934MEDIUM5.3In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP serve...
CVE-2020-3850CRITICAL9.8A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A...
CVE-2020-3849CRITICAL9.8A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A...
CVE-2020-3848CRITICAL9.8A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A...
CVE-2020-3847CRITICAL9.8An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A rem...
CVE-2020-1949MEDIUM6.1Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elem...
CVE-2020-1943MEDIUM6.1Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
CVE-2020-10204HIGH7.2Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
CVE-2020-10203MEDIUM4.8Sonatype Nexus Repository before 3.21.2 allows XSS.
CVE-2020-10199HIGH8.8Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
CVE-2020-9785HIGH7.8Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.4 and iPa...
CVE-2020-9784MEDIUM4.3A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use a...
CVE-2020-9783HIGH8.8A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, t...
CVE-2020-9781MEDIUM5.3The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPa...
CVE-2020-9780LOW3.3The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPa...
CVE-2020-9777MEDIUM5.3An issue existed in the selection of video file by Mail. The issue was fixed by selecting the latest version of a video....
CVE-2020-9776LOW3.3This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A malicious application ...
CVE-2020-9775MEDIUM5.3An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved stat...
CVE-2020-9773LOW3.3The issue was addressed with improved handling of icon caches. This issue is fixed in iOS 14.0 and iPadOS 14.0. A malici...
CVE-2020-9770MEDIUM6.5A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now