2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-22721HIGH7.8A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary c...
CVE-2020-9228HIGH7.5FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, ...
CVE-2020-17462HIGH7.8CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a...
CVE-2020-16205HIGH7.2Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code ...
CVE-2020-4662HIGH8.8IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication v...
CVE-2020-7360HIGH7.3An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before ...
CVE-2020-24346HIGH7.8njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.
CVE-2020-24345HIGH7.8JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the ve...
CVE-2020-24344HIGH7.1JerryScript through 2.3.0 has a (function({a=arguments}){const arguments}) buffer over-read.
CVE-2020-24343HIGH7.8Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.
CVE-2020-24342HIGH7.8Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_ca...
CVE-2020-24331HIGH7.8An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user sti...
CVE-2020-24330HIGH7.8An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the...
CVE-2020-0261HIGH7.8In C2 flame devices, there is a possible bypass of seccomp due to a missing configuration file. This could lead to local...
CVE-2020-15947HIGH8.8A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows...
CVE-2020-15925HIGH8.8A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers t...
CVE-2020-16087HIGH8.6An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Win...
CVE-2020-8688HIGH7.5Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potential...
CVE-2020-8687HIGH7.8Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB...
CVE-2020-8681HIGH7.8Out of bounds write in system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authen...
CVE-2020-8680HIGH7Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potenti...
CVE-2020-12301HIGH8.2Improper initialization in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a pri...
CVE-2020-12300HIGH8.2Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may all...
CVE-2020-12299HIGH8.2Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a p...
CVE-2020-0559HIGH7.8Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now