2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28501HIGH7.5This affects the package es6-crawler-detect before 3.1.3. No limitation of user agent string length supplied to regex op...
CVE-2020-13963CRITICAL9.8SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authenticati...
CVE-2020-27171MEDIUM6An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resulta...
CVE-2020-27170MEDIUM4.7An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds spec...
CVE-2020-4635MEDIUM5.3IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames.
CVE-2020-25097HIGH8.6An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trust...
CVE-2020-6578MEDIUM6.1Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_...
CVE-2020-6577CRITICAL9.8The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.
CVE-2020-9367HIGH7.8The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinvent...
CVE-2020-36144MEDIUM5.3Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escapi...
CVE-2020-26886HIGH7.8Softaculous before 5.5.7 is affected by a code execution vulnerability because of External Initialization of Trusted Var...
CVE-2020-26797HIGH7.5Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_Channel...
CVE-2020-35492HIGH7.8A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can pro...
CVE-2020-14516CRITICAL10In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementa...
CVE-2020-27827HIGH7.5A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when al...
CVE-2020-26155HIGH7.8Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions fo...
CVE-2020-17457MEDIUM5.4Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FI...
CVE-2020-35456MEDIUM5.5The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and m...
CVE-2020-35455HIGH7.8The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Sha...
CVE-2020-35454MEDIUM6.8The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an ...
CVE-2020-14358Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-8111Rejected reason: Unused CVE for 2020
CVE-2020-8106Rejected reason: Unused CVE for 2020
CVE-2020-28873HIGH7.5Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user ...
CVE-2020-15766Rejected reason: Unused CVE for 2020

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now