2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-23039MEDIUM5.4Folder Lock v3.4.5 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Create Folder func...
CVE-2020-23038HIGH7.5Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the pat...
CVE-2020-23037CRITICAL9.8Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to...
CVE-2020-23036MEDIUM5.9MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handlin...
CVE-2020-14263LOW3.9"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron App...
CVE-2020-27304CRITICAL9.8The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the b...
CVE-2020-11303HIGH8.6Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon A...
CVE-2020-12141CRITICAL9.1An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service an...
CVE-2020-29622HIGH7.5A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mou...
CVE-2020-8291MEDIUM6.1A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
CVE-2020-4951LOW3.3IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain...
CVE-2020-19964MEDIUM6.5A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new...
CVE-2020-19962MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.3...
CVE-2020-19961HIGH7.5A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da...
CVE-2020-19960HIGH7.5A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da...
CVE-2020-19959HIGH7.5A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da...
CVE-2020-19957HIGH7.5A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da...
CVE-2020-19954HIGH7.5An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read...
CVE-2020-22724CRITICAL9.8A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 an...
CVE-2020-22679MEDIUM5.5Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS)...
CVE-2020-22678MEDIUM5.5An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-base...
CVE-2020-22677MEDIUM5.5An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which c...
CVE-2020-22675MEDIUM5.5An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which ca...
CVE-2020-22674MEDIUM5.5An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_i...
CVE-2020-22673MEDIUM5.5Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now