2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4235MEDIUM5.4IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2020-4214HIGH7.5IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by ...
CVE-2020-4208CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key...
CVE-2020-4206HIGH8.8IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the syste...
CVE-2020-11414HIGH7.5An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUploa...
CVE-2020-10595CRITICAL9.8pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental pr...
CVE-2020-11113HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-11112HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-11111HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9055MEDIUM5.4Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could al...
CVE-2020-7611CRITICAL9.8All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable...
CVE-2020-5289MEDIUM6.5In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have...
CVE-2020-5284MEDIUM4.3Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access...
CVE-2020-11106MEDIUM6.1An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION...
CVE-2020-11105CRITICAL9.8An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw po...
CVE-2020-11104MEDIUM5.3An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable i...
CVE-2020-10374CRITICAL9.8A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command exe...
CVE-2020-5726HIGH7.5The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A rem...
CVE-2020-5725MEDIUM5.9The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo...
CVE-2020-5724HIGH7.5The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo...
CVE-2020-5723CRITICAL9.8The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta...
CVE-2020-5275HIGH8.1In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs...
CVE-2020-5274MEDIUM5.4In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHa...
CVE-2020-5255MEDIUM4.3In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected version...
CVE-2020-7610CRITICAL9.8All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknow...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now