2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-12769MEDIUM5.5An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via co...
CVE-2020-12768MEDIUM5.5An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a memory leak, aka CID-...
CVE-2020-12767MEDIUM5.5exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
CVE-2020-12765MEDIUM5.3Solis Miolo 2.0 allows index.php?module=install&action=view&item= Directory Traversal.
CVE-2020-12764MEDIUM5.3Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal.
CVE-2020-6616MEDIUM6.5Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (P...
CVE-2020-11006MEDIUM5.4In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed wh...
CVE-2020-12737MEDIUM6.5An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using d...
CVE-2020-10690MEDIUM6.4There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cde...
CVE-2020-11541MEDIUM5.5In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local ...
CVE-2020-12680MEDIUM5.5Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the execut...
CVE-2020-12718MEDIUM5.4In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulne...
CVE-2020-11056MEDIUM6.3In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields...
CVE-2020-11055MEDIUM5.4In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A ...
CVE-2020-11053MEDIUM6.1In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the prox...
CVE-2020-4430MEDIUM4.3IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories...
CVE-2020-12708MEDIUM6.1Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web scrip...
CVE-2020-12707MEDIUM6.1An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only secur...
CVE-2020-12706MEDIUM5.4Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web scrip...
CVE-2020-12705MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
CVE-2020-12704MEDIUM6.1UliCMS before 2020.2 has PageController stored XSS.
CVE-2020-12703MEDIUM6.1UliCMS before 2020.2 has XSS during PackageController uninstall.
CVE-2020-11047MEDIUM5.9In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A ma...
CVE-2020-11042MEDIUM5.9In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading...
CVE-2020-5751MEDIUM5.4Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now