2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-18144CRITICAL9.8SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.
CVE-2020-27379MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF ...
CVE-2020-25445HIGH7.8The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input ...
CVE-2020-25444MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About...
CVE-2020-20231MEDIUM6.5Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet p...
CVE-2020-0417HIGH7.8In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable Pend...
CVE-2020-19722MEDIUM6.5An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a direct copy to NULL pointer deref...
CVE-2020-19721MEDIUM6.5A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while runn...
CVE-2020-19720MEDIUM6.5An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, lea...
CVE-2020-19719MEDIUM6.5A buffer overflow vulnerability in Ap4ElstAtom.cpp of Bento 1.5.1-628 leads to a denial of service (DOS).
CVE-2020-19718MEDIUM6.5An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading...
CVE-2020-19717MEDIUM6.5An unhandled memory allocation failure in Core/Ap48bdlAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, lea...
CVE-2020-19716MEDIUM6.5A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS)...
CVE-2020-19715Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13110 Reason: This candidate is a duplicate of C...
CVE-2020-20252MEDIUM6.5Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat pro...
CVE-2020-22907HIGH7.5Stack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Den...
CVE-2020-22886HIGH7.5Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to caus...
CVE-2020-22885HIGH7.5Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to...
CVE-2020-22884CRITICAL9.8Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to ...
CVE-2020-22882HIGH7.5Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted...
CVE-2020-22876HIGH7.5Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is...
CVE-2020-22875CRITICAL9.8Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute ar...
CVE-2020-22874CRITICAL9.8Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute a...
CVE-2020-22873CRITICAL9.8Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute...
CVE-2020-20250MEDIUM6.5Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat pro...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now