2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27940MEDIUM4.3This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0....
CVE-2020-11301HIGH7.5Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosur...
CVE-2020-11264CRITICAL9.8Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packe...
CVE-2020-29012MEDIUM5.3An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse...
CVE-2020-19855MEDIUM6.1phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
CVE-2020-19853CRITICAL9.8BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
CVE-2020-19769HIGH7.5A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from...
CVE-2020-19768HIGH7.5A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from...
CVE-2020-19767HIGH7.5A lack of target address verification in the destroycontract() function of 0xRACER 1.0 allows attackers to steal tokens ...
CVE-2020-19766HIGH7.5The time check operation of PepeAuctionSale 1.0 can be rendered ineffective by assigning a large number to the _duration...
CVE-2020-19765HIGH7.5An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a re...
CVE-2020-19752HIGH7.5The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
CVE-2020-19751CRITICAL9.1An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read...
CVE-2020-19750HIGH7.5An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read.
CVE-2020-7865CRITICAL9.8A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download ...
CVE-2020-7832CRITICAL9.8A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download ...
CVE-2020-7819HIGH7.5A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthentic...
CVE-2020-19131HIGH7.5Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the...
CVE-2020-7877HIGH8.8A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' comma...
CVE-2020-15939MEDIUM4.3An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allo...
CVE-2020-18048CRITICAL9.8An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered i...
CVE-2020-13929HIGH7.5Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to...
CVE-2020-20349MEDIUM5.4WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background link...
CVE-2020-20348MEDIUM5.4WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu managem...
CVE-2020-20347MEDIUM5.4WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management mo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now