2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9382MEDIUM5.4An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for th...
CVE-2020-9381HIGH7.5controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/w...
CVE-2020-1938CRITICAL9.8When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc...
CVE-2020-1935MEDIUM4.8In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach t...
CVE-2020-1937HIGH8.8Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run m...
CVE-2020-9374CRITICAL9.8On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit...
CVE-2020-9369HIGH7.5Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files,...
CVE-2020-5245HIGH8.8Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privilege...
CVE-2020-5244HIGH7.5In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Aut...
CVE-2020-9366CRITICAL9.8A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted outp...
CVE-2020-9365HIGH7.5An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function i...
CVE-2020-9363HIGH7.8The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects End...
CVE-2020-9362HIGH7.8The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. Th...
CVE-2020-4222CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us...
CVE-2020-4213CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us...
CVE-2020-4212CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us...
CVE-2020-4211CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us...
CVE-2020-4210CRITICAL9.8IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By us...
CVE-2020-8131HIGH7.5Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem a...
CVE-2020-8130MEDIUM6.4There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that be...
CVE-2020-5188MEDIUM6.5DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
CVE-2020-5187HIGH8.8DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
CVE-2020-5186MEDIUM5.4DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
CVE-2020-9355CRITICAL9.8danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.
CVE-2020-9354HIGH7.5An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functional...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now