2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27281HIGH7.8A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when proces...
CVE-2020-27277HIGH7.8Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files...
CVE-2020-27275HIGH7.8Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project fi...
CVE-2020-25659MEDIUM5.9python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing o...
CVE-2020-24003LOW3.3Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process ...
CVE-2020-23960HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attac...
CVE-2020-17534HIGH7There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in ...
CVE-2020-35483HIGH7.8AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the applic...
CVE-2020-2508HIGH7.2A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows...
CVE-2020-26118HIGH8.8In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentic...
CVE-2020-23630HIGH8.8A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
CVE-2020-23849MEDIUM6.1Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
CVE-2020-23644MEDIUM6.1XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.
CVE-2020-23643MEDIUM6.1XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.
CVE-2020-26800MEDIUM5.5A stack overflow vulnerability in Aleth Ethereum C++ client version <= 1.8.0 using a specially crafted a config.json fil...
CVE-2020-17509HIGH7.5ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or ...
CVE-2020-17508HIGH7.5The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic S...
CVE-2020-13922MEDIUM6.5Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users p...
CVE-2020-11995CRITICAL9.8A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code exec...
CVE-2020-35727MEDIUM5.4Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35726MEDIUM6.1Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35725MEDIUM6.1Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35724MEDIUM5.4Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35723MEDIUM5.4Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35722MEDIUM6.5CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/cr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now