2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6425MEDIUM5.4Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced ...
CVE-2020-6424HIGH8.8Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap co...
CVE-2020-6422HIGH8.8Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap co...
CVE-2020-6420HIGH8.8Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass sam...
CVE-2020-10364HIGH7.5The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusa...
CVE-2020-8497MEDIUM5.3In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format an...
CVE-2020-10793HIGH8.8CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the ...
CVE-2020-6650HIGH8.8UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or ...
CVE-2020-1951MEDIUM5.5A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
CVE-2020-1950MEDIUM5.5A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23...
CVE-2020-10661CRITICAL9.1HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing neste...
CVE-2020-10660MEDIUM5.3HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Gro...
CVE-2020-10593HIGH7.5Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Servi...
CVE-2020-10592HIGH7.5Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Servi...
CVE-2020-9752CRITICAL9.8Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system...
CVE-2020-10821MEDIUM4.8Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
CVE-2020-10820MEDIUM4.8Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
CVE-2020-10819MEDIUM4.8Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.
CVE-2020-10818HIGH7.2Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the ...
CVE-2020-10812MEDIUM5.5An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() locate...
CVE-2020-10811MEDIUM5.5An issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5O__layout_decode(...
CVE-2020-10810MEDIUM5.5An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5AC_unpin_entry() loc...
CVE-2020-10809MEDIUM5.5An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located...
CVE-2020-10808HIGH8.8Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint....
CVE-2020-10807MEDIUM5.3auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now