2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7390MEDIUM5.4Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First N...
CVE-2020-7389HIGH7.2Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS command...
CVE-2020-7388CRITICAL9.8Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side au...
CVE-2020-7387MEDIUM5.3Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe componen...
CVE-2020-36033CRITICAL9.8SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php.
CVE-2020-5370MEDIUM6.8Dell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulnerability. A remote a...
CVE-2020-5316HIGH7.8Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home...
CVE-2020-19499HIGH8.8An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Servic...
CVE-2020-19498HIGH8.8Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibl...
CVE-2020-19497HIGH8.8Integer overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows...
CVE-2020-19492HIGH7.8There is a floating point exception in ReadImage that leads to a Segmentation fault in sam2p 0.49.4. A crafted input wil...
CVE-2020-19491HIGH7.8There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will...
CVE-2020-19490MEDIUM5.5tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
CVE-2020-19488MEDIUM5.5An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due ...
CVE-2020-19481MEDIUM5.5An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_p...
CVE-2020-19475MEDIUM5.5An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of...
CVE-2020-19474MEDIUM5.5An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service ...
CVE-2020-19473MEDIUM5.5An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of S...
CVE-2020-19472MEDIUM5.5An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of S...
CVE-2020-19471MEDIUM5.5An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of S...
CVE-2020-19470MEDIUM5.5An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Servi...
CVE-2020-19469MEDIUM5.5An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service...
CVE-2020-19468MEDIUM5.5An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Ser...
CVE-2020-19467MEDIUM5.5An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denia...
CVE-2020-19466MEDIUM5.5An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denia...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now