2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9453 | MEDIUM | 5.5 | 0.4% | Feb 5, 2021 | In Epson iProjection v2.30, the driver file EMP_MPAU.sys allows local users to cause a denial of service (BSOD) or possi... |
| CVE-2020-12122 | HIGH | 7.8 | 0.5% | Feb 5, 2021 | In Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of se... |
| CVE-2020-10858 | MEDIUM | 5.3 | 1.1% | Feb 5, 2021 | Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permissi... |
| CVE-2020-10857 | CRITICAL | 9.8 | 3.0% | Feb 5, 2021 | Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remo... |
| CVE-2020-10554 | HIGH | 7.5 | 0.8% | Feb 5, 2021 | An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an ob... |
| CVE-2020-10553 | MEDIUM | 5.5 | 0.2% | Feb 5, 2021 | An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\Psyprax32\PPScreen.ini contains a hash for the l... |
| CVE-2020-10552 | HIGH | 8.1 | 1.1% | Feb 5, 2021 | An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and pa... |
| CVE-2020-10375 | MEDIUM | 5.5 | 0.3% | Feb 5, 2021 | An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format th... |
| CVE-2020-9014 | MEDIUM | 5.5 | 0.4% | Feb 5, 2021 | In Epson iProjection v2.30, the driver file (EMP_NSAU.sys) allows local users to cause a denial of service (BSOD) via cr... |
| CVE-2020-18750 | HIGH | 7.8 | 0.5% | Feb 5, 2021 | Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file. |
| CVE-2020-10234 | MEDIUM | 6.5 | 3.8% | Feb 5, 2021 | The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL t... |
| CVE-2020-18737 | MEDIUM | 6.1 | 1.3% | Feb 5, 2021 | An issue was discovered in Typora 0.9.67. There is an XSS vulnerability that causes Remote Code Execution. |
| CVE-2020-4832 | MEDIUM | 5.5 | 0.3% | Feb 5, 2021 | IBM PowerHA 7.2 could allow a local attacker to obtain sensitive information from temporary directories after a discover... |
| CVE-2020-8807 | MEDIUM | 5.3 | 1.0% | Feb 5, 2021 | In Electric Coin Company Zcashd before 2.1.1-1, the time offset between messages could be leveraged to obtain sensitive ... |
| CVE-2020-8806 | HIGH | 7.5 | 1.0% | Feb 5, 2021 | Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid c... |
| CVE-2020-36241 | MEDIUM | 5.5 | 0.6% | Feb 5, 2021 | autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Dir... |
| CVE-2020-35765 | HIGH | 8.8 | 28.2% | Feb 5, 2021 | doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows ... |
| CVE-2020-18717 | CRITICAL | 9.8 | 3.6% | Feb 5, 2021 | SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filter... |
| CVE-2020-18716 | CRITICAL | 9.8 | 1.8% | Feb 5, 2021 | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAc... |
| CVE-2020-18715 | — | — | — | Feb 5, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-18714 | CRITICAL | 9.8 | 1.3% | Feb 5, 2021 | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordMo... |
| CVE-2020-18713 | CRITICAL | 9.8 | 1.8% | Feb 5, 2021 | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in custom... |
| CVE-2020-10539 | CRITICAL | 9.8 | 1.5% | Feb 5, 2021 | An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user... |
| CVE-2020-10538 | MEDIUM | 5.5 | 0.3% | Feb 5, 2021 | An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the databa... |
| CVE-2020-10537 | HIGH | 7.8 | 0.3% | Feb 5, 2021 | An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP p... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now