2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4235 | MEDIUM | 5.4 | 0.7% | Mar 31, 2020 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2020-4214 | HIGH | 7.5 | 1.6% | Mar 31, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by ... |
| CVE-2020-4208 | CRITICAL | 9.8 | 1.8% | Mar 31, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key... |
| CVE-2020-4206 | HIGH | 8.8 | 4.6% | Mar 31, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the syste... |
| CVE-2020-11414 | HIGH | 7.5 | 1.0% | Mar 31, 2020 | An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUploa... |
| CVE-2020-10595 | CRITICAL | 9.8 | 4.8% | Mar 31, 2020 | pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental pr... |
| CVE-2020-11113 | HIGH | 8.8 | 6.3% | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-11112 | HIGH | 8.8 | 3.7% | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-11111 | HIGH | 8.8 | 3.6% | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-9055 | MEDIUM | 5.4 | 0.5% | Mar 30, 2020 | Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could al... |
| CVE-2020-7611 | CRITICAL | 9.8 | 1.8% | Mar 30, 2020 | All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable... |
| CVE-2020-5289 | MEDIUM | 6.5 | 1.3% | Mar 30, 2020 | In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have... |
| CVE-2020-5284 | MEDIUM | 4.3 | 43.4% | Mar 30, 2020 | Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access... |
| CVE-2020-11106 | MEDIUM | 6.1 | 0.9% | Mar 30, 2020 | An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION... |
| CVE-2020-11105 | CRITICAL | 9.8 | 2.0% | Mar 30, 2020 | An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw po... |
| CVE-2020-11104 | MEDIUM | 5.3 | 1.5% | Mar 30, 2020 | An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable i... |
| CVE-2020-10374 | CRITICAL | 9.8 | 4.7% | Mar 30, 2020 | A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command exe... |
| CVE-2020-5726 | HIGH | 7.5 | 4.2% | Mar 30, 2020 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A rem... |
| CVE-2020-5725 | MEDIUM | 5.9 | 1.7% | Mar 30, 2020 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo... |
| CVE-2020-5724 | HIGH | 7.5 | 11.9% | Mar 30, 2020 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo... |
| CVE-2020-5723 | CRITICAL | 9.8 | 5.7% | Mar 30, 2020 | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta... |
| CVE-2020-5275 | HIGH | 8.1 | 1.1% | Mar 30, 2020 | In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs... |
| CVE-2020-5274 | MEDIUM | 5.4 | 1.2% | Mar 30, 2020 | In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHa... |
| CVE-2020-5255 | MEDIUM | 4.3 | 1.3% | Mar 30, 2020 | In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected version... |
| CVE-2020-7610 | CRITICAL | 9.8 | 2.2% | Mar 30, 2020 | All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknow... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now