2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-11126CRITICAL9.1Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, ...
CVE-2020-35442CRITICAL9.8FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background v...
CVE-2020-35441CRITICAL9.8FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.cl...
CVE-2020-4561CRITICAL10IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This a...
CVE-2020-10666CRITICAL9.8The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote ...
CVE-2020-15782CRITICAL9.8A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Co...
CVE-2020-27847CRITICAL9.8A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validat...
CVE-2020-15180CRITICAL9A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for co...
CVE-2020-12403CRITICAL9.1A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chac...
CVE-2020-27832CRITICAL9A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a r...
CVE-2020-13601CRITICAL9.8Possible read out of bounds in dns read. Zephyr versions >= 1.14.2, >= 2.3.0 contain Out-of-bounds Read (CWE-125). For m...
CVE-2020-10064CRITICAL9.8Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buff...
CVE-2020-20907CRITICAL9.1MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/syst...
CVE-2020-28910CRITICAL9.8Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalati...
CVE-2020-28908CRITICAL9.8Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.
CVE-2020-28907CRITICAL9.8Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Exec...
CVE-2020-28904CRITICAL9.8Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via i...
CVE-2020-28902CRITICAL9.8Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
CVE-2020-28901CRITICAL9.8Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vecto...
CVE-2020-28900CRITICAL9.8Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows...
CVE-2020-25409CRITICAL9.8Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
CVE-2020-36331CRITICAL9.1A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The h...
CVE-2020-36330CRITICAL9.1A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. ...
CVE-2020-36329CRITICAL9.8A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early....
CVE-2020-36328CRITICAL9.8A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is poss...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now