2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23039 | MEDIUM | 5.4 | 0.6% | Oct 22, 2021 | Folder Lock v3.4.5 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Create Folder func... |
| CVE-2020-23038 | HIGH | 7.5 | 2.9% | Oct 22, 2021 | Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the pat... |
| CVE-2020-23037 | CRITICAL | 9.8 | 1.4% | Oct 22, 2021 | Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to... |
| CVE-2020-23036 | MEDIUM | 5.9 | 1.1% | Oct 22, 2021 | MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handlin... |
| CVE-2020-14263 | LOW | 3.9 | 0.2% | Oct 21, 2021 | "HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron App... |
| CVE-2020-27304 | CRITICAL | 9.8 | 3.1% | Oct 21, 2021 | The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the b... |
| CVE-2020-11303 | HIGH | 8.6 | 0.7% | Oct 20, 2021 | Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon A... |
| CVE-2020-12141 | CRITICAL | 9.1 | 1.5% | Oct 19, 2021 | An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service an... |
| CVE-2020-29622 | HIGH | 7.5 | 1.1% | Oct 19, 2021 | A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mou... |
| CVE-2020-8291 | MEDIUM | 6.1 | 0.6% | Oct 18, 2021 | A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks. |
| CVE-2020-4951 | LOW | 3.3 | 0.3% | Oct 15, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain... |
| CVE-2020-19964 | MEDIUM | 6.5 | 0.6% | Oct 14, 2021 | A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new... |
| CVE-2020-19962 | MEDIUM | 5.4 | 0.6% | Oct 14, 2021 | A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.3... |
| CVE-2020-19961 | HIGH | 7.5 | 1.8% | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da... |
| CVE-2020-19960 | HIGH | 7.5 | 1.5% | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da... |
| CVE-2020-19959 | HIGH | 7.5 | 1.5% | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da... |
| CVE-2020-19957 | HIGH | 7.5 | 1.5% | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da... |
| CVE-2020-19954 | HIGH | 7.5 | 1.2% | Oct 14, 2021 | An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read... |
| CVE-2020-22724 | CRITICAL | 9.8 | 5.4% | Oct 14, 2021 | A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 an... |
| CVE-2020-22679 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS)... |
| CVE-2020-22678 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-base... |
| CVE-2020-22677 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which c... |
| CVE-2020-22675 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which ca... |
| CVE-2020-22674 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_i... |
| CVE-2020-22673 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now