2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28900CRITICAL9.8Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows...
CVE-2020-26006MEDIUM6.1Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
CVE-2020-25411MEDIUM6.5Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing...
CVE-2020-25409CRITICAL9.8Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
CVE-2020-25408MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows ...
CVE-2020-23768HIGH7.5An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interfa...
CVE-2020-23766MEDIUM6.5An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolut...
CVE-2020-23765HIGH7.2A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If a...
CVE-2020-36332HIGH7.5A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memor...
CVE-2020-36331CRITICAL9.1A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The h...
CVE-2020-36330CRITICAL9.1A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. ...
CVE-2020-36329CRITICAL9.8A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early....
CVE-2020-36328CRITICAL9.8A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is poss...
CVE-2020-27211MEDIUM5.7Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The fl...
CVE-2020-27212HIGH7STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP)...
CVE-2020-27208MEDIUM6.8The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4....
CVE-2020-12061CRITICAL9.8An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the sec...
CVE-2020-27209HIGH7.5The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversar...
CVE-2020-18220HIGH7.5Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not...
CVE-2020-21345MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a rem...
CVE-2020-35580HIGH7.5A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated us...
CVE-2020-21057HIGH8.1Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the syst...
CVE-2020-21056MEDIUM4.3Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via ...
CVE-2020-21055MEDIUM6.5A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.vi...
CVE-2020-21054MEDIUM6.1Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now