2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-24949HIGH8.8Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr...
CVE-2020-7729HIGH7.1The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load(...
CVE-2020-5420HIGH7.7Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause de...
CVE-2020-5386HIGH7.5Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker c...
CVE-2020-5369HIGH8.8Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalat...
CVE-2020-7830HIGH7.8RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lac...
CVE-2020-5779HIGH7.5A flaw in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) relates to invalid parameter handling when calling strcpy_s...
CVE-2020-5778HIGH7.5A flaw exists in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) due to improper validation of user-supplied data whe...
CVE-2020-25045HIGH7.8Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were...
CVE-2020-25044HIGH7.1Kaspersky Virus Removal Tool (KVRT) prior to 15.0.23.0 was vulnerable to arbitrary file corruption that could provide an...
CVE-2020-25043HIGH7.1The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow...
CVE-2020-15167HIGH8.6In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an...
CVE-2020-15094HIGH8.8In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on...
CVE-2020-24028HIGH8.8ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, passwor...
CVE-2020-23830HIGH7.1A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 a...
CVE-2020-14209HIGH8.8Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio...
CVE-2020-25079HIGH8.8An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.c...
CVE-2020-25078HIGH7.5An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate...
CVE-2020-16602HIGH8.1Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra...
CVE-2020-5622HIGH7.5Shadankun Server Security Type (excluding normal blocking method types) Ver.1.5.3 and earlier allows remote attackers to...
CVE-2020-24955HIGH7.8SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivilege...
CVE-2020-6152HIGH7.8A code execution vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.7. A spe...
CVE-2020-5776HIGH8.8Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is poss...
CVE-2020-25070HIGH8.8USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.
CVE-2020-16208HIGH8.8The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different config...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now