2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13947 | MEDIUM | 6.1 | 79.0% | Feb 8, 2021 | An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console... |
| CVE-2020-36152 | HIGH | 8.8 | 2.3% | Feb 8, 2021 | Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary... |
| CVE-2020-36151 | MEDIUM | 6.5 | 1.2% | Feb 8, 2021 | Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to ... |
| CVE-2020-36150 | MEDIUM | 6.5 | 1.2% | Feb 8, 2021 | Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overfl... |
| CVE-2020-36149 | MEDIUM | 6.5 | 1.2% | Feb 8, 2021 | Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointe... |
| CVE-2020-36148 | MEDIUM | 6.5 | 1.2% | Feb 8, 2021 | Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointe... |
| CVE-2020-24944 | HIGH | 7.5 | 1.5% | Feb 8, 2021 | picoquic (before 3rd of July 2020) allows attackers to cause a denial of service (infinite loop) via a crafted QUIC fram... |
| CVE-2020-7786 | CRITICAL | 9.8 | 2.0% | Feb 8, 2021 | This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js. |
| CVE-2020-7785 | CRITICAL | 9.8 | 2.5% | Feb 8, 2021 | This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js. |
| CVE-2020-7782 | CRITICAL | 9.8 | 2.5% | Feb 8, 2021 | This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection ... |
| CVE-2020-6649 | CRITICAL | 9.8 | 1.5% | Feb 8, 2021 | An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attack... |
| CVE-2020-16629 | CRITICAL | 9.8 | 1.4% | Feb 8, 2021 | PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the a... |
| CVE-2020-26052 | MEDIUM | 5.4 | 0.7% | Feb 8, 2021 | Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple par... |
| CVE-2020-26051 | CRITICAL | 9.8 | 2.4% | Feb 8, 2021 | College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters ... |
| CVE-2020-1779 | MEDIUM | 4.9 | 1.0% | Feb 8, 2021 | When dynamic templates are used (OTRSTicketForms), admin can use OTRS tags which are not masked properly and can reveal ... |
| CVE-2020-35700 | HIGH | 8.8 | 2.3% | Feb 8, 2021 | A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNM... |
| CVE-2020-11920 | CRITICAL | 9.8 | 4.2% | Feb 8, 2021 | An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in t... |
| CVE-2020-11915 | MEDIUM | 6.8 | 0.6% | Feb 8, 2021 | An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&r... |
| CVE-2020-36243 | HIGH | 8.8 | 64.1% | Feb 7, 2021 | The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To... |
| CVE-2020-36242 | CRITICAL | 9.1 | 6.7% | Feb 7, 2021 | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB... |
| CVE-2020-9205 | MEDIUM | 4.9 | 0.6% | Feb 6, 2021 | There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerabi... |
| CVE-2020-9118 | MEDIUM | 6.8 | 0.2% | Feb 6, 2021 | There is an insufficient integrity check vulnerability in Huawei Sound X Product. The system does not check certain soft... |
| CVE-2020-5812 | MEDIUM | 5.9 | 0.5% | Feb 6, 2021 | Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which c... |
| CVE-2020-14312 | MEDIUM | 5.9 | 1.2% | Feb 6, 2021 | A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all version... |
| CVE-2020-11836 | MEDIUM | 5.5 | 0.1% | Feb 6, 2021 | OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability. The “adb sh... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now