2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-14940HIGH7.5An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading ...
CVE-2020-14939HIGH7.8An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts th...
CVE-2020-4031HIGH7.5In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility ...
CVE-2020-14945HIGH8.8A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an auth...
CVE-2020-14990HIGH7.1IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Cl...
CVE-2020-14049HIGH7.5Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber...
CVE-2020-13158HIGH7.5Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parame...
CVE-2020-11520HIGH7.8The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory ad...
CVE-2020-11519HIGH7.8The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sect...
CVE-2020-10740HIGH7.5A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible ...
CVE-2020-10736HIGH8An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr d...
CVE-2020-6644HIGH8.1An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpi...
CVE-2020-4066HIGH7.2In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are un...
CVE-2020-13887HIGH8.8documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to...
CVE-2020-13279HIGH8.6Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system
CVE-2020-8933HIGH7.8A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on...
CVE-2020-8907HIGH7.8A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on...
CVE-2020-8903HIGH7.8A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on...
CVE-2020-14461HIGH8.6Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
CVE-2020-14204HIGH8.2In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local f...
CVE-2020-14203HIGH8.8WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users ...
CVE-2020-14969HIGH7.5app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the att...
CVE-2020-14966HIGH7.5An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signature...
CVE-2020-8102HIGH8.8Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an ex...
CVE-2020-3676HIGH7.8Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now