2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16268HIGH8.8The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevate...
CVE-2020-35735MEDIUM4.7Vidyo 02-09-/D allows clickjacking via the portal/ URI.
CVE-2020-9223HIGH7.5There is a denial of service vulnerability in some Huawei smartphones. Due to the improper processing of received abnorm...
CVE-2020-9208MEDIUM6.5There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authenticat...
CVE-2020-9207HIGH7.8There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not veri...
CVE-2020-9125MEDIUM6.7There is an out-of-bound read vulnerability in huawei smartphone Mate 30 versions earlier than 10.1.0.156 (C00E155R7P2)....
CVE-2020-9124HIGH7.5There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker...
CVE-2020-9094HIGH7.5There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with ...
CVE-2020-9093MEDIUM5.5There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specif...
CVE-2020-35774MEDIUM5.4server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configu...
CVE-2020-35773HIGH8.8The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
CVE-2020-28283CRITICAL9.8Prototype pollution vulnerability in 'libnested' versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of se...
CVE-2020-28282CRITICAL9.8Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may l...
CVE-2020-28281CRITICAL9.8Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denia...
CVE-2020-28280CRITICAL9.8Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of se...
CVE-2020-28279CRITICAL9.8Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of ...
CVE-2020-28278CRITICAL9.8Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service...
CVE-2020-1848MEDIUM5.5There is a resource management error vulnerability in Jackman-AL00D versions 8.2.0.185(C00R2P1). Local attackers constru...
CVE-2020-29471MEDIUM4.8OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as ...
CVE-2020-29470MEDIUM4.8OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an...
CVE-2020-28277CRITICAL9.8Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service an...
CVE-2020-28276CRITICAL9.8Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of servic...
CVE-2020-28275Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-5807HIGH7.5An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the Factor...
CVE-2020-5806MEDIUM5.5An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseL...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now