2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-27800HIGH7.8A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
CVE-2020-27799HIGH7.8A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mac...
CVE-2020-27796HIGH7.8A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafte...
CVE-2020-35511HIGH7.8A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file...
CVE-2020-27795HIGH7.5A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or w...
CVE-2020-27793HIGH7.5An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an atta...
CVE-2020-27792HIGH7.1A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c fi...
CVE-2020-1756HIGH7.2In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin...
CVE-2020-14322HIGH7.5In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitig...
CVE-2020-14321HIGH8.8In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role wi...
CVE-2020-10728HIGH7.8A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all us...
CVE-2020-23622HIGH7.5An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service ...
CVE-2020-21641HIGH7.5Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote a...
CVE-2020-21365HIGH7.5Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose...
CVE-2020-6998HIGH8.6The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 ...
CVE-2020-28422HIGH7.8All versions of package git-archive are vulnerable to Command Injection via the exports function.
CVE-2020-14126HIGH7.5Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sens...
CVE-2020-14114HIGH7.5information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of s...
CVE-2020-21406HIGH7.5An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service vi...
CVE-2020-21405HIGH7.5An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColo...
CVE-2020-16093HIGH7.5In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when conn...
CVE-2020-7641HIGH7.8This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying pr...
CVE-2020-14127HIGH7.5A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow a...
CVE-2020-4159HIGH7.5IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to...
CVE-2020-4157HIGH7.5IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, wh...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now