2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2100MEDIUM5.8Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service at...
CVE-2020-2099HIGH8.6Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent ...
CVE-2020-7965HIGH8.8flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receivin...
CVE-2020-8428HIGH7.1fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a...
CVE-2020-8426MEDIUM5.4The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info ...
CVE-2020-8425MEDIUM6.5Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
CVE-2020-8424HIGH8.8Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php...
CVE-2020-5227HIGH7.5Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supp...
CVE-2020-5215HIGH7.5In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation...
CVE-2020-8421MEDIUM6.1An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
CVE-2020-8420HIGH8.8An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates cause...
CVE-2020-8419HIGH8.8An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause ...
CVE-2020-8417HIGH8.8The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import me...
CVE-2020-8315MEDIUM5.5In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launc...
CVE-2020-5211CRITICAL9.8In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a...
CVE-2020-4207CRITICAL9.8IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by impr...
CVE-2020-8112HIGH8.8opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in th...
CVE-2020-5214CRITICAL9.8In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash...
CVE-2020-5213CRITICAL9.8In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow result...
CVE-2020-5212CRITICAL9.8In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow...
CVE-2020-5210HIGH7.8In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a cr...
CVE-2020-5209HIGH7.8In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or re...
CVE-2020-8086CRITICAL9.8The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP addre...
CVE-2020-1940HIGH7.5The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 a...
CVE-2020-7934MEDIUM5.4In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now