2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19417 | HIGH | 8.8 | 2.7% | Mar 10, 2021 | Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform ... |
| CVE-2020-1921 | HIGH | 7.5 | 1.2% | Mar 10, 2021 | In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that th... |
| CVE-2020-1919 | HIGH | 7.5 | 1.2% | Mar 10, 2021 | Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument pass... |
| CVE-2020-1918 | HIGH | 7.5 | 1.2% | Mar 10, 2021 | In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the r... |
| CVE-2020-1917 | CRITICAL | 9.8 | 1.4% | Mar 10, 2021 | xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated strin... |
| CVE-2020-1916 | CRITICAL | 9.8 | 1.4% | Mar 10, 2021 | An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, result... |
| CVE-2020-0025 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In deletePackageVersionedInternal of PackageManagerService.java, there is a possible way to exit Screen Pinning due to a... |
| CVE-2020-5016 | MEDIUM | 6.5 | 2.3% | Mar 10, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys... |
| CVE-2020-4717 | MEDIUM | 5.5 | 0.3% | Mar 10, 2021 | A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permissio... |
| CVE-2020-35752 | MEDIUM | 5.4 | 0.9% | Mar 10, 2021 | Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post tit... |
| CVE-2020-28705 | MEDIUM | 4.3 | 0.6% | Mar 10, 2021 | FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /page... |
| CVE-2020-24791 | CRITICAL | 9.8 | 2.6% | Mar 10, 2021 | FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could ... |
| CVE-2020-23722 | HIGH | 8.8 | 1.0% | Mar 10, 2021 | An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privil... |
| CVE-2020-23721 | MEDIUM | 5.4 | 0.6% | Mar 10, 2021 | An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages... |
| CVE-2020-13959 | MEDIUM | 6.1 | 6.4% | Mar 10, 2021 | The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered... |
| CVE-2020-13936 | HIGH | 8.8 | 22.7% | Mar 10, 2021 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands w... |
| CVE-2020-29238 | HIGH | 7.5 | 16.7% | Mar 10, 2021 | An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi... |
| CVE-2020-35524 | HIGH | 7.8 | 1.9% | Mar 9, 2021 | A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A spec... |
| CVE-2020-35523 | HIGH | 7.8 | 1.9% | Mar 9, 2021 | An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to in... |
| CVE-2020-35522 | MEDIUM | 5.5 | 1.6% | Mar 9, 2021 | In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting ... |
| CVE-2020-35521 | MEDIUM | 5.5 | 1.2% | Mar 9, 2021 | A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort,... |
| CVE-2020-28952 | HIGH | 7.5 | 1.3% | Mar 9, 2021 | An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique S... |
| CVE-2020-27225 | HIGH | 7.8 | 0.3% | Mar 9, 2021 | In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to t... |
| CVE-2020-28150 | MEDIUM | 6.1 | 0.9% | Mar 9, 2021 | I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an exter... |
| CVE-2020-8357 | MEDIUM | 5.5 | 0.2% | Mar 9, 2021 | A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow conf... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now