2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27280HIGH7.8A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an atta...
CVE-2020-27098MEDIUM5.5In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissi...
CVE-2020-27097MEDIUM5.5In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to l...
CVE-2020-26941MEDIUM5.5A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwr...
CVE-2020-25737HIGH7.8An elevation of privilege vulnerability exists in Hackolade versions prior 4.2.0 on Windows has an issue in specific dep...
CVE-2020-25173HIGH7.8An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reol...
CVE-2020-25169HIGH7.5The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink serv...
CVE-2020-24549HIGH8.8openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
CVE-2020-24085MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHo...
CVE-2020-23826HIGH8.8The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection vi...
CVE-2020-23449HIGH7.5newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexCon...
CVE-2020-23448CRITICAL9.8newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginIntercep...
CVE-2020-23447MEDIUM6.1newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their a...
CVE-2020-23262CRITICAL9.8An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in thro...
CVE-2020-23162HIGH7.5Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows re...
CVE-2020-23161MEDIUM6.5Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to ...
CVE-2020-23160HIGH8.8Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to...
CVE-2020-23014MEDIUM5.4APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtyp...
CVE-2020-22643HIGH7.2Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. A...
CVE-2020-21147MEDIUM4.8RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious ...
CVE-2020-21146MEDIUM6.1Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript ...
CVE-2020-20269CRITICAL9.8A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0....
CVE-2020-17524Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-17522MEDIUM5.8When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0,...
CVE-2020-16236HIGH7.8FPWIN Pro is vulnerable to an out-of-bounds read vulnerability when a user opens a maliciously crafted project file, whi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now