2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27940 | MEDIUM | 4.3 | 0.7% | Sep 8, 2021 | This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0.... |
| CVE-2020-11301 | HIGH | 7.5 | 11.1% | Sep 8, 2021 | Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosur... |
| CVE-2020-11264 | CRITICAL | 9.8 | 13.2% | Sep 8, 2021 | Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packe... |
| CVE-2020-29012 | MEDIUM | 5.3 | 0.5% | Sep 8, 2021 | An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse... |
| CVE-2020-19855 | MEDIUM | 6.1 | 0.6% | Sep 8, 2021 | phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php. |
| CVE-2020-19853 | CRITICAL | 9.8 | 1.1% | Sep 8, 2021 | BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php. |
| CVE-2020-19769 | HIGH | 7.5 | 0.5% | Sep 7, 2021 | A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from... |
| CVE-2020-19768 | HIGH | 7.5 | 0.5% | Sep 7, 2021 | A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from... |
| CVE-2020-19767 | HIGH | 7.5 | 1.1% | Sep 7, 2021 | A lack of target address verification in the destroycontract() function of 0xRACER 1.0 allows attackers to steal tokens ... |
| CVE-2020-19766 | HIGH | 7.5 | 0.9% | Sep 7, 2021 | The time check operation of PepeAuctionSale 1.0 can be rendered ineffective by assigning a large number to the _duration... |
| CVE-2020-19765 | HIGH | 7.5 | 0.9% | Sep 7, 2021 | An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a re... |
| CVE-2020-19752 | HIGH | 7.5 | 1.6% | Sep 7, 2021 | The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference. |
| CVE-2020-19751 | CRITICAL | 9.1 | 1.3% | Sep 7, 2021 | An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read... |
| CVE-2020-19750 | HIGH | 7.5 | 1.1% | Sep 7, 2021 | An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read. |
| CVE-2020-7865 | CRITICAL | 9.8 | 0.9% | Sep 7, 2021 | A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download ... |
| CVE-2020-7832 | CRITICAL | 9.8 | 0.9% | Sep 7, 2021 | A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download ... |
| CVE-2020-7819 | HIGH | 7.5 | 1.4% | Sep 7, 2021 | A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthentic... |
| CVE-2020-19131 | HIGH | 7.5 | 2.3% | Sep 7, 2021 | Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the... |
| CVE-2020-7877 | HIGH | 8.8 | 0.8% | Sep 7, 2021 | A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' comma... |
| CVE-2020-15939 | MEDIUM | 4.3 | 0.6% | Sep 6, 2021 | An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allo... |
| CVE-2020-18048 | CRITICAL | 9.8 | 1.7% | Sep 2, 2021 | An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered i... |
| CVE-2020-13929 | HIGH | 7.5 | 3.0% | Sep 2, 2021 | Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to... |
| CVE-2020-20349 | MEDIUM | 5.4 | 0.5% | Sep 1, 2021 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background link... |
| CVE-2020-20348 | MEDIUM | 5.4 | 0.5% | Sep 1, 2021 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu managem... |
| CVE-2020-20347 | MEDIUM | 5.4 | 0.5% | Sep 1, 2021 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management mo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now