2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11925HIGH8.8An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a u...
CVE-2020-11922MEDIUM4.3An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller serve...
CVE-2020-19619MEDIUM5.4Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
CVE-2020-19618MEDIUM5.4Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.
CVE-2020-19617MEDIUM5.4Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.
CVE-2020-19616MEDIUM5.4Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.
CVE-2020-19613HIGH7.5Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version...
CVE-2020-9149MEDIUM5.5An application error verification vulnerability exists in a component interface of Huawei Smartphone. Local attackers ca...
CVE-2020-9148MEDIUM5.5An application bypass mechanism vulnerability exists in a component interface of Huawei Smartphone. Local attackers can ...
CVE-2020-9147HIGH7.8A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit th...
CVE-2020-9146MEDIUM5.5A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit th...
CVE-2020-36286MEDIUM5.3The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before versio...
CVE-2020-36238MEDIUM5.3The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before versio...
CVE-2020-24550MEDIUM6.1An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted website...
CVE-2020-35308CRITICAL9.8CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute mal...
CVE-2020-28173HIGH7.2Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_setting...
CVE-2020-28172CRITICAL9.8A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin ...
CVE-2020-24995HIGH7.8Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to ...
CVE-2020-24391CRITICAL9.8mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this m...
CVE-2020-4944MEDIUM5.5IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore p...
CVE-2020-4884MEDIUM5.5IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be rea...
CVE-2020-4848MEDIUM5.4IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compa...
CVE-2020-15075HIGH7.1OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access ...
CVE-2020-20545MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Zhiyuan G6 Government Collaboration System V6.1SP1, via the 'method' paramet...
CVE-2020-19643MEDIUM6.1Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now