2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28587 | HIGH | 7.8 | 0.9% | Feb 23, 2021 | A specially crafted document can cause the document parser to copy data from a particular record type into a static-size... |
| CVE-2020-27782 | HIGH | 7.5 | 1.3% | Feb 23, 2021 | A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an... |
| CVE-2020-26609 | MEDIUM | 5.4 | 0.9% | Feb 23, 2021 | fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain... |
| CVE-2020-25161 | HIGH | 8.8 | 1.5% | Feb 23, 2021 | The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path... |
| CVE-2020-16243 | HIGH | 7.8 | 12.0% | Feb 23, 2021 | Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. ... |
| CVE-2020-7847 | HIGH | 8 | 0.5% | Feb 23, 2021 | The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can b... |
| CVE-2020-4953 | MEDIUM | 4.3 | 1.1% | Feb 23, 2021 | IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's int... |
| CVE-2020-28432 | — | — | — | Feb 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-28431 | — | — | — | Feb 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-28430 | — | — | — | Feb 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-28429 | CRITICAL | 9.8 | 63.3% | Feb 23, 2021 | All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geoj... |
| CVE-2020-14359 | HIGH | 7.3 | 0.9% | Feb 23, 2021 | A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an a... |
| CVE-2020-8902 | MEDIUM | 4.3 | 0.3% | Feb 23, 2021 | Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can u... |
| CVE-2020-13697 | MEDIUM | 6.1 | 0.8% | Feb 23, 2021 | An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic ... |
| CVE-2020-29075 | MEDIUM | 6.5 | 7.8% | Feb 23, 2021 | Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) a... |
| CVE-2020-27819 | MEDIUM | 5.5 | 0.8% | Feb 23, 2021 | An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer derefere... |
| CVE-2020-27768 | LOW | 3.3 | 1.4% | Feb 23, 2021 | In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-priva... |
| CVE-2020-25690 | HIGH | 8.8 | 1.3% | Feb 23, 2021 | An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certai... |
| CVE-2020-35852 | MEDIUM | 6.1 | 1.1% | Feb 23, 2021 | Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatb... |
| CVE-2020-36232 | MEDIUM | 5 | 1.0% | Feb 22, 2021 | The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from vers... |
| CVE-2020-29453 | MEDIUM | 5.3 | 23.1% | Feb 22, 2021 | The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 befor... |
| CVE-2020-29448 | MEDIUM | 5.3 | 2.3% | Feb 22, 2021 | The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, ... |
| CVE-2020-22475 | MEDIUM | 6.8 | 0.5% | Feb 22, 2021 | "Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application compo... |
| CVE-2020-22474 | MEDIUM | 6.5 | 1.0% | Feb 22, 2021 | In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local fi... |
| CVE-2020-24175 | HIGH | 7.8 | 1.8% | Feb 22, 2021 | Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows at... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now