2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25621HIGH8.4An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security...
CVE-2020-25620HIGH7.8An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accou...
CVE-2020-14254HIGH7.5TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enab...
CVE-2020-29363HIGH7.5An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC p...
CVE-2020-29361HIGH7.5An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array ...
CVE-2020-25618HIGH8.8An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because ...
CVE-2020-25617HIGH8.8An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Trave...
CVE-2020-28458HIGH7.3All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.i...
CVE-2020-5683HIGH7.5Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1...
CVE-2020-5682HIGH7.5Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series)...
CVE-2020-26258HIGH7.7XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Fo...
CVE-2020-35122HIGH7.5An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could by...
CVE-2020-35121HIGH8.8An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could in...
CVE-2020-35381HIGH7.5jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a G...
CVE-2020-35380HIGH7.5GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.
CVE-2020-28072HIGH7.2A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker c...
CVE-2020-25759HIGH8.8An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interfa...
CVE-2020-25758HIGH8.8An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could al...
CVE-2020-25757HIGH8.8A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being...
CVE-2020-25195HIGH7.5The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on t...
CVE-2020-29487HIGH7.5An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are th...
CVE-2020-29481HIGH8.8An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing gr...
CVE-2020-29479HIGH8.8An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the...
CVE-2020-29569HIGH8.8An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block b...
CVE-2020-27055HIGH7.5In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigController2.java, there...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now