2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-19417HIGH8.8Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform ...
CVE-2020-1921HIGH7.5In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that th...
CVE-2020-1919HIGH7.5Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument pass...
CVE-2020-1918HIGH7.5In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the r...
CVE-2020-1917CRITICAL9.8xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated strin...
CVE-2020-1916CRITICAL9.8An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, result...
CVE-2020-0025HIGH7.8In deletePackageVersionedInternal of PackageManagerService.java, there is a possible way to exit Screen Pinning due to a...
CVE-2020-5016MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys...
CVE-2020-4717MEDIUM5.5A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permissio...
CVE-2020-35752MEDIUM5.4Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post tit...
CVE-2020-28705MEDIUM4.3FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /page...
CVE-2020-24791CRITICAL9.8FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could ...
CVE-2020-23722HIGH8.8An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privil...
CVE-2020-23721MEDIUM5.4An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages...
CVE-2020-13959MEDIUM6.1The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered...
CVE-2020-13936HIGH8.8An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands w...
CVE-2020-29238HIGH7.5An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi...
CVE-2020-35524HIGH7.8A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A spec...
CVE-2020-35523HIGH7.8An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to in...
CVE-2020-35522MEDIUM5.5In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting ...
CVE-2020-35521MEDIUM5.5A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort,...
CVE-2020-28952HIGH7.5An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique S...
CVE-2020-27225HIGH7.8In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to t...
CVE-2020-28150MEDIUM6.1I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an exter...
CVE-2020-8357MEDIUM5.5A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow conf...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now