2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13947MEDIUM6.1An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console...
CVE-2020-36152HIGH8.8Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary...
CVE-2020-36151MEDIUM6.5Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to ...
CVE-2020-36150MEDIUM6.5Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overfl...
CVE-2020-36149MEDIUM6.5Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointe...
CVE-2020-36148MEDIUM6.5Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointe...
CVE-2020-24944HIGH7.5picoquic (before 3rd of July 2020) allows attackers to cause a denial of service (infinite loop) via a crafted QUIC fram...
CVE-2020-7786CRITICAL9.8This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
CVE-2020-7785CRITICAL9.8This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
CVE-2020-7782CRITICAL9.8This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection ...
CVE-2020-6649CRITICAL9.8An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attack...
CVE-2020-16629CRITICAL9.8PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the a...
CVE-2020-26052MEDIUM5.4Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple par...
CVE-2020-26051CRITICAL9.8College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters ...
CVE-2020-1779MEDIUM4.9When dynamic templates are used (OTRSTicketForms), admin can use OTRS tags which are not masked properly and can reveal ...
CVE-2020-35700HIGH8.8A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNM...
CVE-2020-11920CRITICAL9.8An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in t...
CVE-2020-11915MEDIUM6.8An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&r...
CVE-2020-36243HIGH8.8The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To...
CVE-2020-36242CRITICAL9.1In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB...
CVE-2020-9205MEDIUM4.9There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerabi...
CVE-2020-9118MEDIUM6.8There is an insufficient integrity check vulnerability in Huawei Sound X Product. The system does not check certain soft...
CVE-2020-5812MEDIUM5.9Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which c...
CVE-2020-14312MEDIUM5.9A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all version...
CVE-2020-11836MEDIUM5.5OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability. The “adb sh...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now