2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28587HIGH7.8A specially crafted document can cause the document parser to copy data from a particular record type into a static-size...
CVE-2020-27782HIGH7.5A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an...
CVE-2020-26609MEDIUM5.4fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain...
CVE-2020-25161HIGH8.8The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path...
CVE-2020-16243HIGH7.8Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. ...
CVE-2020-7847HIGH8The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can b...
CVE-2020-4953MEDIUM4.3IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's int...
CVE-2020-28432Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-28431Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-28430Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-28429CRITICAL9.8All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geoj...
CVE-2020-14359HIGH7.3A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an a...
CVE-2020-8902MEDIUM4.3Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can u...
CVE-2020-13697MEDIUM6.1An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic ...
CVE-2020-29075MEDIUM6.5Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) a...
CVE-2020-27819MEDIUM5.5An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer derefere...
CVE-2020-27768LOW3.3In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-priva...
CVE-2020-25690HIGH8.8An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certai...
CVE-2020-35852MEDIUM6.1Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatb...
CVE-2020-36232MEDIUM5The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from vers...
CVE-2020-29453MEDIUM5.3The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 befor...
CVE-2020-29448MEDIUM5.3The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, ...
CVE-2020-22475MEDIUM6.8"Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application compo...
CVE-2020-22474MEDIUM6.5In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local fi...
CVE-2020-24175HIGH7.8Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows at...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now