2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-13849HIGH7.5The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client...
CVE-2020-13848HIGH7.5Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a cr...
CVE-2020-12851HIGH8.1Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells...
CVE-2020-12847HIGH7.2Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with...
CVE-2020-11681HIGH8.1Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged us...
CVE-2020-11679HIGH8.8Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionalit...
CVE-2020-7661HIGH7.5all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long stri...
CVE-2020-13836HIGH7.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path ...
CVE-2020-13834HIGH7.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folde...
CVE-2020-13830HIGH7.5An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Sa...
CVE-2020-13829HIGH7.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid ...
CVE-2020-13815HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indire...
CVE-2020-13813HIGH7.8An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted D...
CVE-2020-13812HIGH7.8An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted D...
CVE-2020-13811HIGH7.8An issue was discovered in Foxit Studio Photo before 3.6.6.922. It has an out-of-bounds write via a crafted TIFF file.
CVE-2020-13692HIGH7.7PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
CVE-2020-13822HIGH7.7The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' byte...
CVE-2020-13810HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modifie...
CVE-2020-13809HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in ...
CVE-2020-13808HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-re...
CVE-2020-13807HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a...
CVE-2020-13806HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execu...
CVE-2020-13803HIGH7.5An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypa...
CVE-2020-4509HIGH7.6IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r...
CVE-2020-13818HIGH7.5In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now