2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35518 | MEDIUM | 5.3 | 1.5% | Mar 26, 2021 | When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or n... |
| CVE-2020-35508 | MEDIUM | 4.5 | 0.2% | Mar 26, 2021 | A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/... |
| CVE-2020-27829 | MEDIUM | 5.5 | 1.2% | Mar 26, 2021 | A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.... |
| CVE-2020-35856 | MEDIUM | 4.8 | 0.7% | Mar 26, 2021 | SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page. |
| CVE-2020-19626 | MEDIUM | 5.4 | 0.8% | Mar 26, 2021 | Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or H... |
| CVE-2020-19625 | CRITICAL | 9.8 | 13.1% | Mar 26, 2021 | Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attack... |
| CVE-2020-25840 | MEDIUM | 6.1 | 0.6% | Mar 26, 2021 | Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The ... |
| CVE-2020-28346 | HIGH | 7.5 | 1.2% | Mar 26, 2021 | ACRN through 2.2 has a devicemodel/hw/pci/virtio/virtio.c NULL Pointer Dereference. |
| CVE-2020-23517 | MEDIUM | 6.1 | 7.1% | Mar 26, 2021 | Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers... |
| CVE-2020-10584 | HIGH | 7.5 | 2.2% | Mar 25, 2021 | A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows ... |
| CVE-2020-10583 | HIGH | 8.8 | 2.8% | Mar 25, 2021 | The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attacke... |
| CVE-2020-10582 | CRITICAL | 9.8 | 1.6% | Mar 25, 2021 | A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows r... |
| CVE-2020-10581 | HIGH | 7.5 | 1.3% | Mar 25, 2021 | Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (... |
| CVE-2020-10580 | HIGH | 8.8 | 3.9% | Mar 25, 2021 | A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows re... |
| CVE-2020-10579 | HIGH | 7.5 | 2.2% | Mar 25, 2021 | A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows rem... |
| CVE-2020-35502 | HIGH | 7.5 | 2.4% | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is ... |
| CVE-2020-6790 | HIGH | 7.8 | 0.3% | Mar 25, 2021 | Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to a... |
| CVE-2020-6789 | HIGH | 7.8 | 0.3% | Mar 25, 2021 | Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including versio... |
| CVE-2020-6788 | HIGH | 7.8 | 0.3% | Mar 25, 2021 | Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and includi... |
| CVE-2020-6787 | HIGH | 7.8 | 0.3% | Mar 25, 2021 | Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including versio... |
| CVE-2020-6786 | HIGH | 7.8 | 0.3% | Mar 25, 2021 | Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Recording Manager installer up to and inclu... |
| CVE-2020-6785 | HIGH | 7.8 | 0.3% | Mar 25, 2021 | Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0... |
| CVE-2020-6771 | HIGH | 7.8 | 0.3% | Mar 25, 2021 | Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 poten... |
| CVE-2020-1946 | CRITICAL | 9.8 | 6.1% | Mar 25, 2021 | In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands w... |
| CVE-2020-7852 | HIGH | 7.8 | 0.9% | Mar 24, 2021 | DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now