2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35518MEDIUM5.3When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or n...
CVE-2020-35508MEDIUM4.5A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/...
CVE-2020-27829MEDIUM5.5A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7....
CVE-2020-35856MEDIUM4.8SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
CVE-2020-19626MEDIUM5.4Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or H...
CVE-2020-19625CRITICAL9.8Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attack...
CVE-2020-25840MEDIUM6.1Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The ...
CVE-2020-28346HIGH7.5ACRN through 2.2 has a devicemodel/hw/pci/virtio/virtio.c NULL Pointer Dereference.
CVE-2020-23517MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers...
CVE-2020-10584HIGH7.5A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows ...
CVE-2020-10583HIGH8.8The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attacke...
CVE-2020-10582CRITICAL9.8A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows r...
CVE-2020-10581HIGH7.5Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (...
CVE-2020-10580HIGH8.8A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows re...
CVE-2020-10579HIGH7.5A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows rem...
CVE-2020-35502HIGH7.5A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is ...
CVE-2020-6790HIGH7.8Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to a...
CVE-2020-6789HIGH7.8Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including versio...
CVE-2020-6788HIGH7.8Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and includi...
CVE-2020-6787HIGH7.8Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including versio...
CVE-2020-6786HIGH7.8Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Recording Manager installer up to and inclu...
CVE-2020-6785HIGH7.8Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0...
CVE-2020-6771HIGH7.8Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 poten...
CVE-2020-1946CRITICAL9.8In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands w...
CVE-2020-7852HIGH7.8DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now