2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-28503CRITICAL9.8The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.
CVE-2020-13963CRITICAL9.8SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authenticati...
CVE-2020-6577CRITICAL9.8The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.
CVE-2020-14516CRITICAL10In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementa...
CVE-2020-11299CRITICAL9.8Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdrago...
CVE-2020-11227CRITICAL9.8Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer i...
CVE-2020-11222CRITICAL9.1Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon...
CVE-2020-11192CRITICAL9.8Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Comp...
CVE-2020-11190CRITICAL9.1Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon...
CVE-2020-11189CRITICAL9.1Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon...
CVE-2020-11188CRITICAL9.1Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon...
CVE-2020-11171CRITICAL9.1Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon...
CVE-2020-11166CRITICAL9.1Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC...
CVE-2020-28899CRITICAL9.1The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote un...
CVE-2020-24264CRITICAL9.8Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. T...
CVE-2020-28149CRITICAL9.6myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The compone...
CVE-2020-24877CRITICAL9.8A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access rest...
CVE-2020-35358CRITICAL9.8DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, bot...
CVE-2020-36282CRITICAL9.8JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result i...
CVE-2020-29045CRITICAL9.8The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of ...
CVE-2020-1900CRITICAL9.8When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property arr...
CVE-2020-1917CRITICAL9.8xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated strin...
CVE-2020-1916CRITICAL9.8An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, result...
CVE-2020-24791CRITICAL9.8FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could ...
CVE-2020-28050CRITICAL9.1Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to co...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now