2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7988 | HIGH | 8.8 | 0.7% | Mar 4, 2020 | An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any u... |
| CVE-2020-9364 | MEDIUM | 5.3 | 3.1% | Mar 4, 2020 | An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!... |
| CVE-2020-5251 | MEDIUM | 5.3 | 0.8% | Mar 4, 2020 | In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the... |
| CVE-2020-10029 | MEDIUM | 5.5 | 0.8% | Mar 4, 2020 | The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input ... |
| CVE-2020-5536 | HIGH | 8.8 | 0.6% | Mar 4, 2020 | OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentica... |
| CVE-2020-5535 | HIGH | 8.8 | 0.9% | Mar 4, 2020 | OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary... |
| CVE-2020-1734 | HIGH | 7.4 | 0.4% | Mar 3, 2020 | A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses s... |
| CVE-2020-5403 | HIGH | 7.5 | 1.1% | Mar 3, 2020 | Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be ... |
| CVE-2020-5404 | MEDIUM | 5.9 | 0.7% | Mar 3, 2020 | The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorr... |
| CVE-2020-1893 | HIGH | 7.5 | 1.1% | Mar 3, 2020 | Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This... |
| CVE-2020-1892 | HIGH | 8.1 | 1.1% | Mar 3, 2020 | Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially l... |
| CVE-2020-1888 | HIGH | 7.5 | 1.1% | Mar 3, 2020 | Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DO... |
| CVE-2020-4198 | MEDIUM | 5.4 | 0.6% | Mar 3, 2020 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2020-4197 | LOW | 2.4 | 0.3% | Mar 3, 2020 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 allows web pages to be stored locally which can be read by another user on the syst... |
| CVE-2020-4196 | MEDIUM | 5.4 | 0.6% | Mar 3, 2020 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2020-9751 | CRITICAL | 9.1 | 0.5% | Mar 3, 2020 | Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and exec... |
| CVE-2020-10018 | CRITICAL | 9.8 | 5.0% | Mar 2, 2020 | WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory co... |
| CVE-2020-8778 | MEDIUM | 5.4 | 2.6% | Mar 2, 2020 | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, ... |
| CVE-2020-8777 | MEDIUM | 5.4 | 3.2% | Mar 2, 2020 | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, ... |
| CVE-2020-8776 | MEDIUM | 5.4 | 2.7% | Mar 2, 2020 | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a ... |
| CVE-2020-8437 | HIGH | 7.5 | 12.0% | Mar 2, 2020 | The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which al... |
| CVE-2020-8013 | LOW | 2.5 | 0.3% | Mar 2, 2020 | A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterpr... |
| CVE-2020-1731 | CRITICAL | 9.8 | 1.3% | Mar 2, 2020 | A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator gene... |
| CVE-2020-8500 | HIGH | 7.2 | 3.5% | Mar 2, 2020 | In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Exten... |
| CVE-2020-6764 | — | — | — | Mar 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now