2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36049HIGH7.5socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet beca...
CVE-2020-36048HIGH7.5Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the lo...
CVE-2020-13452CRITICAL9.8In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to ...
CVE-2020-13451CRITICAL9.8An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to over...
CVE-2020-13450CRITICAL9.8A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and ...
CVE-2020-13449HIGH7.5A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any con...
CVE-2020-35745HIGH8.8PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attac...
CVE-2020-17500CRITICAL9.8Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of...
CVE-2020-6656HIGH7.8Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vuln...
CVE-2020-6655HIGH7.8The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability....
CVE-2020-4898HIGH7.5IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an a...
CVE-2020-4897MEDIUM5.3IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacke...
CVE-2020-4896MEDIUM6.5IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validati...
CVE-2020-4895MEDIUM5.4IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This v...
CVE-2020-4893MEDIUM5.9IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request ...
CVE-2020-4892MEDIUM5.4IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2020-27835MEDIUM4.4A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user call...
CVE-2020-25680MEDIUM5.4A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore ...
CVE-2020-13573HIGH7.5A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2...
CVE-2020-25476MEDIUM6.1Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user ...
CVE-2020-28672HIGH7.2MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/...
CVE-2020-26773HIGH8.8Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, auth...
CVE-2020-35114HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corru...
CVE-2020-35113HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evi...
CVE-2020-35112HIGH8.8If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there wa...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now