2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5802HIGH7.5An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a special...
CVE-2020-5801HIGH7.5An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled ex...
CVE-2020-29475MEDIUM4.8nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability ca...
CVE-2020-17533HIGH8.1Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy en...
CVE-2020-25847HIGH8.8This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h...
CVE-2020-35769CRITICAL9.8miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.
CVE-2020-26287HIGH8.7HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can ...
CVE-2020-26286HIGH7.5HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticat...
CVE-2020-13476MEDIUM4.8NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
CVE-2020-13474MEDIUM6.5In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-p...
CVE-2020-13473MEDIUM5.5NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration...
CVE-2020-27172CRITICAL9.8An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file resto...
CVE-2020-35766HIGH7.8The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack agai...
CVE-2020-35730MEDIUM6.1An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack...
CVE-2020-35616HIGH7.5An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause ...
CVE-2020-35615MEDIUM6.3An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy...
CVE-2020-35614MEDIUM5.3An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration a...
CVE-2020-35613CRITICAL9.8An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injectio...
CVE-2020-35612HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validatio...
CVE-2020-35611HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the...
CVE-2020-35610HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the ac...
CVE-2020-26290CRITICAL9.6Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulner...
CVE-2020-25507HIGH7.8An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivi...
CVE-2020-14273HIGH7.5HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its publ...
CVE-2020-27837MEDIUM6.4A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it pos...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now