2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16156HIGH7.8CPAN 2.28 allows Signature Verification Bypass.
CVE-2020-16155MEDIUM6.5The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.
CVE-2020-16154HIGH7.8The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.
CVE-2020-12890MEDIUM6.7Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with...
CVE-2020-19683MEDIUM5.4A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
CVE-2020-19682HIGH8.8A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
CVE-2020-27416CRITICAL9.8Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows r...
CVE-2020-22421MEDIUM6.174CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&k...
CVE-2020-27356MEDIUM5.4The debug-meta-data plugin 1.1.2 for WordPress allows XSS.
CVE-2020-12140HIGH8.8A buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to exe...
CVE-2020-19611MEDIUM6.1Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web s...
CVE-2020-27413MEDIUM4.2An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext user...
CVE-2020-29177CRITICAL9.1Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php.
CVE-2020-29176HIGH7.8An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted...
CVE-2020-36135MEDIUM6.5AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.
CVE-2020-36134MEDIUM6.5AOM v2.0.1 was discovered to contain a segmentation violation via the component aom_dsp/x86/obmc_sad_avx2.c.
CVE-2020-36133HIGH8.8AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h.
CVE-2020-36131HIGH8.8AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c.
CVE-2020-36130MEDIUM6.5AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c.
CVE-2020-36129HIGH8.8AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c.
CVE-2020-27414MEDIUM5.9Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to inform...
CVE-2020-35037MEDIUM6.1The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing the...
CVE-2020-35012HIGH7.2The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL state...
CVE-2020-10627HIGH8.1Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wir...
CVE-2020-7880HIGH8.8The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now