2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16156 | HIGH | 7.8 | 0.8% | Dec 13, 2021 | CPAN 2.28 allows Signature Verification Bypass. |
| CVE-2020-16155 | MEDIUM | 6.5 | 1.0% | Dec 13, 2021 | The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data. |
| CVE-2020-16154 | HIGH | 7.8 | 0.7% | Dec 13, 2021 | The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass. |
| CVE-2020-12890 | MEDIUM | 6.7 | 0.3% | Dec 10, 2021 | Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with... |
| CVE-2020-19683 | MEDIUM | 5.4 | 0.6% | Dec 9, 2021 | A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php. |
| CVE-2020-19682 | HIGH | 8.8 | 0.5% | Dec 9, 2021 | A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php. |
| CVE-2020-27416 | CRITICAL | 9.8 | 1.6% | Dec 8, 2021 | Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows r... |
| CVE-2020-22421 | MEDIUM | 6.1 | 0.8% | Dec 8, 2021 | 74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&k... |
| CVE-2020-27356 | MEDIUM | 5.4 | 1.0% | Dec 7, 2021 | The debug-meta-data plugin 1.1.2 for WordPress allows XSS. |
| CVE-2020-12140 | HIGH | 8.8 | 0.9% | Dec 7, 2021 | A buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to exe... |
| CVE-2020-19611 | MEDIUM | 6.1 | 0.6% | Dec 7, 2021 | Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web s... |
| CVE-2020-27413 | MEDIUM | 4.2 | 0.3% | Dec 7, 2021 | An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext user... |
| CVE-2020-29177 | CRITICAL | 9.1 | 0.9% | Dec 2, 2021 | Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php. |
| CVE-2020-29176 | HIGH | 7.8 | 0.8% | Dec 2, 2021 | An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted... |
| CVE-2020-36135 | MEDIUM | 6.5 | 1.4% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c. |
| CVE-2020-36134 | MEDIUM | 6.5 | 1.1% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a segmentation violation via the component aom_dsp/x86/obmc_sad_avx2.c. |
| CVE-2020-36133 | HIGH | 8.8 | 1.6% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h. |
| CVE-2020-36131 | HIGH | 8.8 | 1.6% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c. |
| CVE-2020-36130 | MEDIUM | 6.5 | 1.4% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c. |
| CVE-2020-36129 | HIGH | 8.8 | 1.4% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c. |
| CVE-2020-27414 | MEDIUM | 5.9 | 1.0% | Dec 2, 2021 | Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to inform... |
| CVE-2020-35037 | MEDIUM | 6.1 | 0.9% | Dec 1, 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing the... |
| CVE-2020-35012 | HIGH | 7.2 | 1.5% | Dec 1, 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL state... |
| CVE-2020-10627 | HIGH | 8.1 | 0.5% | Dec 1, 2021 | Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wir... |
| CVE-2020-7880 | HIGH | 8.8 | 1.6% | Nov 30, 2021 | The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now