2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28503 | CRITICAL | 9.8 | 1.7% | Mar 23, 2021 | The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality. |
| CVE-2020-13963 | CRITICAL | 9.8 | 1.8% | Mar 21, 2021 | SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authenticati... |
| CVE-2020-6577 | CRITICAL | 9.8 | 1.6% | Mar 19, 2021 | The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection. |
| CVE-2020-14516 | CRITICAL | 10 | 4.1% | Mar 18, 2021 | In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementa... |
| CVE-2020-11299 | CRITICAL | 9.8 | 1.1% | Mar 17, 2021 | Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdrago... |
| CVE-2020-11227 | CRITICAL | 9.8 | 0.9% | Mar 17, 2021 | Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer i... |
| CVE-2020-11222 | CRITICAL | 9.1 | 0.9% | Mar 17, 2021 | Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon... |
| CVE-2020-11192 | CRITICAL | 9.8 | 1.1% | Mar 17, 2021 | Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Comp... |
| CVE-2020-11190 | CRITICAL | 9.1 | 1.0% | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon... |
| CVE-2020-11189 | CRITICAL | 9.1 | 1.0% | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon... |
| CVE-2020-11188 | CRITICAL | 9.1 | 1.0% | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon... |
| CVE-2020-11171 | CRITICAL | 9.1 | 1.0% | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon... |
| CVE-2020-11166 | CRITICAL | 9.1 | 0.9% | Mar 17, 2021 | Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC... |
| CVE-2020-28899 | CRITICAL | 9.1 | 1.6% | Mar 16, 2021 | The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote un... |
| CVE-2020-24264 | CRITICAL | 9.8 | 4.1% | Mar 16, 2021 | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. T... |
| CVE-2020-28149 | CRITICAL | 9.6 | 1.9% | Mar 15, 2021 | myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The compone... |
| CVE-2020-24877 | CRITICAL | 9.8 | 2.1% | Mar 15, 2021 | A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access rest... |
| CVE-2020-35358 | CRITICAL | 9.8 | 2.4% | Mar 15, 2021 | DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, bot... |
| CVE-2020-36282 | CRITICAL | 9.8 | 2.8% | Mar 12, 2021 | JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result i... |
| CVE-2020-29045 | CRITICAL | 9.8 | 30.8% | Mar 11, 2021 | The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of ... |
| CVE-2020-1900 | CRITICAL | 9.8 | 1.4% | Mar 11, 2021 | When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property arr... |
| CVE-2020-1917 | CRITICAL | 9.8 | 1.4% | Mar 10, 2021 | xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated strin... |
| CVE-2020-1916 | CRITICAL | 9.8 | 1.4% | Mar 10, 2021 | An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, result... |
| CVE-2020-24791 | CRITICAL | 9.8 | 2.6% | Mar 10, 2021 | FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could ... |
| CVE-2020-28050 | CRITICAL | 9.1 | 5.0% | Mar 5, 2021 | Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to co... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now