2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13849 | HIGH | 7.5 | 2.0% | Jun 4, 2020 | The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client... |
| CVE-2020-13848 | HIGH | 7.5 | 3.5% | Jun 4, 2020 | Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a cr... |
| CVE-2020-12851 | HIGH | 8.1 | 1.5% | Jun 4, 2020 | Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells... |
| CVE-2020-12847 | HIGH | 7.2 | 1.7% | Jun 4, 2020 | Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with... |
| CVE-2020-11681 | HIGH | 8.1 | 1.1% | Jun 4, 2020 | Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged us... |
| CVE-2020-11679 | HIGH | 8.8 | 2.0% | Jun 4, 2020 | Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionalit... |
| CVE-2020-7661 | HIGH | 7.5 | 2.7% | Jun 4, 2020 | all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long stri... |
| CVE-2020-13836 | HIGH | 7.5 | 0.5% | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path ... |
| CVE-2020-13834 | HIGH | 7.5 | 0.3% | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folde... |
| CVE-2020-13830 | HIGH | 7.5 | 0.4% | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Sa... |
| CVE-2020-13829 | HIGH | 7.5 | 0.3% | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid ... |
| CVE-2020-13815 | HIGH | 7.5 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indire... |
| CVE-2020-13813 | HIGH | 7.8 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted D... |
| CVE-2020-13812 | HIGH | 7.8 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted D... |
| CVE-2020-13811 | HIGH | 7.8 | 2.7% | Jun 4, 2020 | An issue was discovered in Foxit Studio Photo before 3.6.6.922. It has an out-of-bounds write via a crafted TIFF file. |
| CVE-2020-13692 | HIGH | 7.7 | 4.1% | Jun 4, 2020 | PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. |
| CVE-2020-13822 | HIGH | 7.7 | 2.6% | Jun 4, 2020 | The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' byte... |
| CVE-2020-13810 | HIGH | 7.5 | 1.1% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modifie... |
| CVE-2020-13809 | HIGH | 7.5 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in ... |
| CVE-2020-13808 | HIGH | 7.5 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-re... |
| CVE-2020-13807 | HIGH | 7.5 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a... |
| CVE-2020-13806 | HIGH | 7.5 | 2.1% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execu... |
| CVE-2020-13803 | HIGH | 7.5 | 0.7% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypa... |
| CVE-2020-4509 | HIGH | 7.6 | 1.5% | Jun 4, 2020 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r... |
| CVE-2020-13818 | HIGH | 7.5 | 37.0% | Jun 4, 2020 | In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now