2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-19465MEDIUM5.5An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of ...
CVE-2020-19464MEDIUM5.5An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due ...
CVE-2020-19463MEDIUM5.5An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to ...
CVE-2020-22150MEDIUM6.1A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute ar...
CVE-2020-22148MEDIUM6.1A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute a...
CVE-2020-23283HIGH7.5Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from...
CVE-2020-23282HIGH7.5SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with...
CVE-2020-21937CRITICAL9.8An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.9736...
CVE-2020-21936MEDIUM5.3An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access ...
CVE-2020-21935CRITICAL9.8A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 R...
CVE-2020-21934HIGH7.5An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the S...
CVE-2020-21933HIGH7.5An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private k...
CVE-2020-21932MEDIUM5.3A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass logi...
CVE-2020-20262MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/no...
CVE-2020-20221MEDIUM6.5Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the ...
CVE-2020-20219MEDIUM6.5Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy pro...
CVE-2020-19609MEDIUM5.5Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF file...
CVE-2020-23284HIGH7.5Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in th...
CVE-2020-25206HIGH7.2The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throu...
CVE-2020-25205MEDIUM6.1The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 is vulnerable to stored XSS in the set_banner() fun...
CVE-2020-35427CRITICAL9.8SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbit...
CVE-2020-15660HIGH8.8Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when...
CVE-2020-7866CRITICAL9.8When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper...
CVE-2020-36431MEDIUM5.5Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm.
CVE-2020-36430HIGH7.8libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now