2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-10936HIGH7.8Sympa before 6.2.56 allows privilege escalation.
CVE-2020-6774HIGH8.8Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attack...
CVE-2020-13630HIGH7ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
CVE-2020-4379HIGH7.5IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2020-4350HIGH7.5IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2020-4349HIGH7.5IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2020-4226HIGH7.5IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to info...
CVE-2020-13386HIGH7.3In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the Smar...
CVE-2020-13623HIGH7.5JerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation.
CVE-2020-13622HIGH7.5JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a P...
CVE-2020-9046HIGH7.8A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user ...
CVE-2020-6830HIGH7.5For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridgin...
CVE-2020-12391HIGH7.5Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed t...
CVE-2020-12387HIGH8.1A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a pot...
CVE-2020-12393HIGH7.8The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c...
CVE-2020-8168HIGH8.8We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie...
CVE-2020-3811HIGH7.5qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
CVE-2020-13482HIGH7.4EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-m...
CVE-2020-13458HIGH8.8An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear...
CVE-2020-13425HIGH7.1TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a...
CVE-2020-13415HIGH7.5An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity...
CVE-2020-13414HIGH7.5An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
CVE-2020-13412HIGH8.8An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token ...
CVE-2020-13398HIGH8.3An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_...
CVE-2020-13396HIGH7.1An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_rea...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now