2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36049 | HIGH | 7.5 | 2.6% | Jan 8, 2021 | socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet beca... |
| CVE-2020-36048 | HIGH | 7.5 | 3.3% | Jan 8, 2021 | Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the lo... |
| CVE-2020-13452 | CRITICAL | 9.8 | 2.7% | Jan 7, 2021 | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to ... |
| CVE-2020-13451 | CRITICAL | 9.8 | 3.0% | Jan 7, 2021 | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to over... |
| CVE-2020-13450 | CRITICAL | 9.8 | 5.6% | Jan 7, 2021 | A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and ... |
| CVE-2020-13449 | HIGH | 7.5 | 4.9% | Jan 7, 2021 | A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any con... |
| CVE-2020-35745 | HIGH | 8.8 | 1.7% | Jan 7, 2021 | PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attac... |
| CVE-2020-17500 | CRITICAL | 9.8 | 3.9% | Jan 7, 2021 | Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of... |
| CVE-2020-6656 | HIGH | 7.8 | 2.7% | Jan 7, 2021 | Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vuln... |
| CVE-2020-6655 | HIGH | 7.8 | 2.7% | Jan 7, 2021 | The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability.... |
| CVE-2020-4898 | HIGH | 7.5 | 0.8% | Jan 7, 2021 | IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an a... |
| CVE-2020-4897 | MEDIUM | 5.3 | 1.6% | Jan 7, 2021 | IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacke... |
| CVE-2020-4896 | MEDIUM | 6.5 | 0.8% | Jan 7, 2021 | IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validati... |
| CVE-2020-4895 | MEDIUM | 5.4 | 0.6% | Jan 7, 2021 | IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This v... |
| CVE-2020-4893 | MEDIUM | 5.9 | 0.6% | Jan 7, 2021 | IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request ... |
| CVE-2020-4892 | MEDIUM | 5.4 | 0.6% | Jan 7, 2021 | IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2020-27835 | MEDIUM | 4.4 | 0.3% | Jan 7, 2021 | A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user call... |
| CVE-2020-25680 | MEDIUM | 5.4 | 0.3% | Jan 7, 2021 | A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore ... |
| CVE-2020-13573 | HIGH | 7.5 | 3.4% | Jan 7, 2021 | A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2... |
| CVE-2020-25476 | MEDIUM | 6.1 | 0.9% | Jan 7, 2021 | Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user ... |
| CVE-2020-28672 | HIGH | 7.2 | 11.7% | Jan 7, 2021 | MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/... |
| CVE-2020-26773 | HIGH | 8.8 | 1.6% | Jan 7, 2021 | Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, auth... |
| CVE-2020-35114 | HIGH | 8.8 | 1.0% | Jan 7, 2021 | Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corru... |
| CVE-2020-35113 | HIGH | 8.8 | 1.3% | Jan 7, 2021 | Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evi... |
| CVE-2020-35112 | HIGH | 8.8 | 1.3% | Jan 7, 2021 | If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there wa... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now