2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9453MEDIUM5.5In Epson iProjection v2.30, the driver file EMP_MPAU.sys allows local users to cause a denial of service (BSOD) or possi...
CVE-2020-12122HIGH7.8In Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of se...
CVE-2020-10858MEDIUM5.3Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permissi...
CVE-2020-10857CRITICAL9.8Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remo...
CVE-2020-10554HIGH7.5An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an ob...
CVE-2020-10553MEDIUM5.5An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\Psyprax32\PPScreen.ini contains a hash for the l...
CVE-2020-10552HIGH8.1An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and pa...
CVE-2020-10375MEDIUM5.5An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format th...
CVE-2020-9014MEDIUM5.5In Epson iProjection v2.30, the driver file (EMP_NSAU.sys) allows local users to cause a denial of service (BSOD) via cr...
CVE-2020-18750HIGH7.8Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.
CVE-2020-10234MEDIUM6.5The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL t...
CVE-2020-18737MEDIUM6.1An issue was discovered in Typora 0.9.67. There is an XSS vulnerability that causes Remote Code Execution.
CVE-2020-4832MEDIUM5.5IBM PowerHA 7.2 could allow a local attacker to obtain sensitive information from temporary directories after a discover...
CVE-2020-8807MEDIUM5.3In Electric Coin Company Zcashd before 2.1.1-1, the time offset between messages could be leveraged to obtain sensitive ...
CVE-2020-8806HIGH7.5Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid c...
CVE-2020-36241MEDIUM5.5autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Dir...
CVE-2020-35765HIGH8.8doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows ...
CVE-2020-18717CRITICAL9.8SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filter...
CVE-2020-18716CRITICAL9.8SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAc...
CVE-2020-18715Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-18714CRITICAL9.8SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordMo...
CVE-2020-18713CRITICAL9.8SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in custom...
CVE-2020-10539CRITICAL9.8An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user...
CVE-2020-10538MEDIUM5.5An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the databa...
CVE-2020-10537HIGH7.8An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP p...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now