2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4675MEDIUM6.5IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attac...
CVE-2020-23707MEDIUM6.5A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file...
CVE-2020-23706MEDIUM6.5A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-fil...
CVE-2020-23705MEDIUM6.5A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cau...
CVE-2020-11634HIGH7.8The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configur...
CVE-2020-11632HIGH7.8The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversa...
CVE-2020-11633CRITICAL9.8The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfi...
CVE-2020-12734HIGH8.1DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment ...
CVE-2020-12733HIGH7.5Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET...
CVE-2020-12732MEDIUM6.5DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.
CVE-2020-25736HIGH7.8Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC...
CVE-2020-25593MEDIUM6.7Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder per...
CVE-2020-15495HIGH7.8Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service ...
CVE-2020-12731HIGH7.5The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whe...
CVE-2020-12730MEDIUM5.3MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
CVE-2020-12729MEDIUM4.6MagicMotion Flamingo 2 has a lack of access control for reading from device descriptors.
CVE-2020-15496HIGH7.8Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.
CVE-2020-36420HIGH7.5Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a mal...
CVE-2020-24133CRITICAL9.8A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows att...
CVE-2020-29157HIGH7.8An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system ...
CVE-2020-18155CRITICAL9.8SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
CVE-2020-18151MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.
CVE-2020-18145MEDIUM6.1Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php.
CVE-2020-29147HIGH7.5A SQL injection vulnerability in wy_controlls/wy_side_visitor.php of Wayang-CMS v1.0 allows attackers to obtain sensitiv...
CVE-2020-29146MEDIUM6.1A cross site scripting (XSS) vulnerability in index.php of Wayang-CMS v1.0 allows attackers to execute arbitrary web scr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now