2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8298CRITICAL9.8fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `cop...
CVE-2020-35636CRITICAL9.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_...
CVE-2020-35628CRITICAL9.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-28636CRITICAL9.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-28601CRITICAL9.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-4975MEDIUM5.4IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2020-4866MEDIUM5.4IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2020-4863MEDIUM5.4IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4857MEDIUM5.4IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4856MEDIUM5.4IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-15938HIGH7.5When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 ...
CVE-2020-35329MEDIUM6.5Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.
CVE-2020-35328MEDIUM5.4Courier Management System 1.0 - 'First Name' Stored XSS
CVE-2020-35327MEDIUM6.5SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST...
CVE-2020-24914CRITICAL9.8A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of th...
CVE-2020-24913CRITICAL9.8A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows ...
CVE-2020-24912MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQ...
CVE-2020-24036HIGH8.8PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote u...
CVE-2020-8296MEDIUM6.7Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
CVE-2020-29047CRITICAL9.8The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an...
CVE-2020-28597HIGH7.5A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting...
CVE-2020-28591MEDIUM6.5An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libsli...
CVE-2020-13558HIGH8.8A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A sp...
CVE-2020-27779HIGH7.5A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an p...
CVE-2020-27749MEDIUM6.7A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line in...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now