2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7988HIGH8.8An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any u...
CVE-2020-9364MEDIUM5.3An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!...
CVE-2020-5251MEDIUM5.3In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the...
CVE-2020-10029MEDIUM5.5The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input ...
CVE-2020-5536HIGH8.8OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentica...
CVE-2020-5535HIGH8.8OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary...
CVE-2020-1734HIGH7.4A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses s...
CVE-2020-5403HIGH7.5Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be ...
CVE-2020-5404MEDIUM5.9The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorr...
CVE-2020-1893HIGH7.5Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This...
CVE-2020-1892HIGH8.1Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially l...
CVE-2020-1888HIGH7.5Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DO...
CVE-2020-4198MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2020-4197LOW2.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 allows web pages to be stored locally which can be read by another user on the syst...
CVE-2020-4196MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2020-9751CRITICAL9.1Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and exec...
CVE-2020-10018CRITICAL9.8WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory co...
CVE-2020-8778MEDIUM5.4Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, ...
CVE-2020-8777MEDIUM5.4Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, ...
CVE-2020-8776MEDIUM5.4Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a ...
CVE-2020-8437HIGH7.5The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which al...
CVE-2020-8013LOW2.5A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterpr...
CVE-2020-1731CRITICAL9.8A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator gene...
CVE-2020-8500HIGH7.2In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Exten...
CVE-2020-6764Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now