2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13675CRITICAL9.8Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all...
CVE-2020-13674MEDIUM6.5The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under som...
CVE-2020-13673MEDIUM6.1The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the f...
CVE-2020-13672MEDIUM6.1Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting...
CVE-2020-13670HIGH7.5Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadat...
CVE-2020-13669MEDIUM6.1Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: D...
CVE-2020-13668MEDIUM6.1Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected...
CVE-2020-7534HIGH8.8A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sen...
CVE-2020-12966MEDIUM5.5AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypt...
CVE-2020-12965HIGH7.5When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using onl...
CVE-2020-12891HIGH7.8AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop i...
CVE-2020-5953HIGH7.5A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI h...
CVE-2020-26208MEDIUM6.1JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images fro...
CVE-2020-8562LOW3.1As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessin...
CVE-2020-36064CRITICAL9.8Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attacker...
CVE-2020-36056MEDIUM5.4Beetel 777VR1-DI Hardware Version REV.1.01 Firmware Version V01.00.09_55 was discovered to contain a cross-site scriptin...
CVE-2020-25905CRITICAL9.8An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1...
CVE-2020-28885HIGH7.2Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje...
CVE-2020-28884HIGH7.2Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje...
CVE-2020-17383CRITICAL9.8A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root l...
CVE-2020-4879CRITICAL9.8IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused b...
CVE-2020-4877CRITICAL9.8IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public field...
CVE-2020-4876HIGH8.2IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2020-4875HIGH8.2IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2020-19861HIGH7.5When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now