2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-12120HIGH7.5The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such a...
CVE-2020-12273HIGH7.5In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
CVE-2020-10996HIGH8.1An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static tr...
CVE-2020-10664HIGH7.5The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference.
CVE-2020-12254HIGH7.8Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlin...
CVE-2020-12070HIGH7.5The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulner...
CVE-2020-11004HIGH7.5SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL quer...
CVE-2020-6828HIGH7.5A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentia...
CVE-2020-6822HIGH8.8On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecod...
CVE-2020-6821HIGH7.5When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method,...
CVE-2020-6820HIGH8.1Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of t...
CVE-2020-6819HIGH8.1Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aw...
CVE-2020-5870HIGH8.1In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for conne...
CVE-2020-12128HIGH7.5DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
CVE-2020-12118HIGH8.2The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parame...
CVE-2020-11012HIGH7.5MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an ...
CVE-2020-5867HIGH8.1In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check...
CVE-2020-5864HIGH7.4In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS...
CVE-2020-12112HIGH7.5BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
CVE-2020-4311HIGH7IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially...
CVE-2020-4202HIGH8.8IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the serv...
CVE-2020-11940HIGH7.5In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positione...
CVE-2020-5571HIGH7.5SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQU...
CVE-2020-12077HIGH8.8The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions wi...
CVE-2020-12076HIGH8.8The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now