2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29164MEDIUM6.1PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
CVE-2020-29163HIGH8.8PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
CVE-2020-28144CRITICAL9.8Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 ...
CVE-2020-35152HIGH7.8Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process run...
CVE-2020-8672HIGH7.8Out of bound read in BIOS firmware for 8th, 9th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 Series ...
CVE-2020-24490MEDIUM6.5Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adja...
CVE-2020-8734MEDIUM6.7Improper input validation in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privilege...
CVE-2020-4081MEDIUM6.1In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
CVE-2020-29662MEDIUM5.3In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
CVE-2020-1910HIGH7.8A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13...
CVE-2020-14255HIGH7.5HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties v...
CVE-2020-14221MEDIUM4.9HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
CVE-2020-7775CRITICAL9.8This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments...
CVE-2020-28498MEDIUM6.8The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec...
CVE-2020-15097CRITICAL9.1loklak is an open-source server application which is able to collect messages from various sources, including twitter. T...
CVE-2020-4934MEDIUM4.3IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send...
CVE-2020-18568CRITICAL9.8The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause ...
CVE-2020-25506CRITICAL9.8D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead ...
CVE-2020-8101HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of A...
CVE-2020-28495HIGH7.3This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to...
CVE-2020-28494HIGH8.6This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type ...
CVE-2020-24335HIGH7.5An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, ...
CVE-2020-1896CRITICAL9.8A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7...
CVE-2020-25036HIGH8.8UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, an...
CVE-2020-25035MEDIUM6.7UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now