2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27362HIGH8.8An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user...
CVE-2020-27361HIGH7.5An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within...
CVE-2020-9158HIGH7.5There is a Missing Cryptographic Step vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability ...
CVE-2020-36407HIGH8.8libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
CVE-2020-36406HIGH8.8uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTre...
CVE-2020-36405HIGH7.8Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken.
CVE-2020-36404HIGH7.8Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl.
CVE-2020-36403HIGH8.8HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).
CVE-2020-36402HIGH7.8Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf68...
CVE-2020-36401HIGH7.8mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
CVE-2020-36400CRITICAL9.8ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.
CVE-2020-36196MEDIUM6.1A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability a...
CVE-2020-36194MEDIUM6.1An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability al...
CVE-2020-18066MEDIUM6.1Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.
CVE-2020-21394HIGH8.8SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename paramet...
CVE-2020-7870HIGH7.2A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to i...
CVE-2020-7869HIGH8.8An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker t...
CVE-2020-7868CRITICAL9.8A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of paramet...
CVE-2020-7871CRITICAL9.8A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exis...
CVE-2020-21142MEDIUM6.1Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.
CVE-2020-22609MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/...
CVE-2020-22608MEDIUM6.1Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.s...
CVE-2020-22607MEDIUM6.1Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in applica...
CVE-2020-20640MEDIUM6.1Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can us...
CVE-2020-23715HIGH8.6Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now